V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
Filters

All vulnerabilities

31 / 31
Preset: exploit×Has exploit×CAPEC: CAPEC-402×Clear all
7.6
CVE-2020-1938DEB KEV
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connectio…
2020-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2024-38856ANC KEV
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: throug…
2024-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2023-22518CVE KEV
All versions of Confluence Data Center and Server are affected by this unexploited vulnerabilit…
2023-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2023-3460CVE
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user …
2023-01-01Pre-auth
EPSS92.8%
pct 99
9.1
CVE-2025-29927ANC
Next.js is a React framework for building full-stack web applications. Starting in version 1.11…
2025-01-01Pre-auth
EPSS92.1%
pct 99
9.8
CVE-2021-28799CVE KEV
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hyb…
2021-01-01KEV
EPSS90.8%
pct 99
8.8
CVE-2023-32707CVE
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform bel…
2023-01-01
EPSS82.7%
pct 99
7.5
CVE-2016-5676CVE
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NET…
2016-01-01Pre-auth
EPSS76.2%
pct 98
3.5
CVE-2013-2113DEB
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows rem…
2013-01-01
EPSS47.4%
pct 97
9.8
CVE-2019-7489CVE
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform …
2019-01-01Pre-auth
EPSS21.1%
pct 95
5.3
CVE-2016-5063CVE
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Window…
2016-01-01Pre-auth
EPSS16.9%
pct 94
7.4
CVE-2024-38821
Spring WebFlux applications that have Spring Security authorization rules on static resources c…
2024-01-01Pre-auth
EPSS13.1%
pct 94
9.1
CVE-2019-1912CVE
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switch…
2019-01-01Pre-auth
EPSS12.2%
pct 93
7.8
CVE-2018-18955AST
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c…
2018-01-01
EPSS9.6%
pct 92
7.5
CVE-2021-25374CVE
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink…
2021-01-01Pre-auth
EPSS7.6%
pct 91
8.8
CVE-2017-11398CVE
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (St…
2017-01-01Pre-auth
EPSS5.4%
pct 89
6.5
CVE-2023-6538CVE
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, throug…
2023-01-01
EPSS5.3%
pct 89
6.3
CVE-2024-12483CVE
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This aff…
2024-01-01Pre-auth
EPSS3.3%
pct 87
5.1
CVE-2024-34463
BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencr…
2024-01-01
EPSS3.1%
pct 86
8.8
CVE-2023-50780ANC
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, wh…
2023-01-01
EPSS2.7%
pct 85
7.2
CVE-2025-20125CVE
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid…
2025-01-01
EPSS2.1%
pct 83
2.7
CVE-2014-6049CVE
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass author…
2014-01-01
EPSS1.2%
pct 78
9.8
CVE-2025-4631
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capab…
2025-01-01Pre-auth
EPSS1.1%
pct 77
6.5
CVE-2025-6713DEB
An unauthorized user may leverage a specially crafted aggregation pipeline to access data witho…
2025-01-01
EPSS0.4%
pct 61
6.5
CVE-2023-5808CVE
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, throug…
2023-01-01
EPSS0.3%
pct 51
5.3
CVE-2025-12720
The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due t…
2025-01-01Pre-auth
EPSS0.1%
pct 31
4.5
CVE-2019-3842AST
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the e…
2019-01-01
EPSS0.1%
pct 25
5.3
CVE-2025-11174
The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all v…
2025-01-01Pre-auth
EPSS0.1%
pct 23
7.4
CVE-2020-7692DEB
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Witho…
2020-01-01Pre-auth
EPSS0.1%
pct 22
5.3
CVE-2018-10906AST
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction b…
2018-01-01
EPSS0.1%
pct 15
4.6
CVE-2016-8776CVE
Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phon…
2016-01-01
EPSS0.0%
pct 8
Select a vulnerability on the left to open the preview.