All vulnerabilities
564 / 564
Sort
9.8
CVE-2024-4358CVE KEV
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthe…
2024-01-01KEV
EPSS97.5%
pct 99
9.8
CVE-2022-24112CVE KEV
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction o…
2022-01-01KEV
EPSS96.2%
pct 99
9.8
CVE-2022-23131DEB KEV
In the case of instances where the SAML SSO authentication is enabled (non-default), session da…
2022-01-01KEV
EPSS95.7%
pct 99
9.8
CVE-2021-29441CVE
Nacos is a platform designed for dynamic service discovery and configuration and service manage…
2021-01-01Pre-auth
EPSS74.8%
pct 99
8.8
CVE-2021-31195MSR
Microsoft Exchange Server Remote Code Execution Vulnerability
2021-01-01MicrosoftPre-auth
EPSS73.7%
pct 99
9.8
CVE-2020-7388CVE
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By e…
2020-01-01Pre-auth
EPSS70.3%
pct 99
10.0
CVE-2024-54085CVE KEV
AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remot…
2024-01-01KEV
EPSS61.2%
pct 99
7.5
CVE-2019-1234CVE
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure…
2019-01-01Pre-auth
EPSS57.9%
pct 98
9.8
CVE-2021-34646CVE
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulne…
2021-01-01Pre-auth
EPSS50.9%
pct 98
8.2
CVE-2025-49002ANC
DataEase is an open source business intelligence and data visualization tool. Versions prior to…
2025-01-01Pre-auth
EPSS40.3%
pct 98
7.5
CVE-2022-34689MSR
Windows CryptoAPI Spoofing Vulnerability
2022-01-01MicrosoftPre-auth
EPSS37.9%
pct 98
9.8
CVE-2018-7842CVE
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modico…
2018-01-01Pre-auth
EPSS35.0%
pct 98
9.8
CVE-2019-19844AST
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitab…
2019-01-01Pre-auth
EPSS34.8%
pct 98
6.5
CVE-2021-21215AST
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remot…
2021-01-01Pre-auth
EPSS34.5%
pct 98
7.5
CVE-2020-10136CVE
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsul…
2020-01-01Pre-auth
EPSS26.5%
pct 97
6.5
CVE-2021-21216AST
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remot…
2021-01-01Pre-auth
EPSS21.8%
pct 97
9.8
CVE-2023-30803CVE
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication…
2023-01-01Pre-auth
EPSS18.2%
pct 96
7.0
CVE-1999-0012CVE
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions f…
1999-01-01Pre-auth
EPSS18.2%
pct 96
8.1
CVE-2024-41107ANC
The CloudStack SAML authentication (disabled by default) does not enforce signature check. In C…
2024-01-01Pre-auth
EPSS17.8%
pct 96
6.5
CVE-2023-50224CVE KEV
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. Thi…
2023-01-01KEV
EPSS17.4%
pct 96
8.8
CVE-2016-0714DEB
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8…
2016-01-01
EPSS13.1%
pct 95
9.8
CVE-2020-17510DEB
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP reques…
2020-01-01Pre-auth
EPSS9.1%
pct 94
9.8
CVE-2022-3180CVE
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and…
2022-01-01Pre-auth
EPSS8.8%
pct 94
5.4
CVE-2023-27964CVE
An authentication issue was addressed with improved state management. This issue is fixed in Ai…
2023-01-01
EPSS8.2%
pct 94
9.8
CVE-2018-5353CVE
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows …
2018-01-01Pre-auth
EPSS8.1%
pct 94
9.6
CVE-2024-12108CVE
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp G…
2024-01-01
EPSS6.8%
pct 93
6.1
CVE-2018-8278MSR
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, a…
2018-01-01MicrosoftPre-auth
EPSS6.4%
pct 92
9.8
CVE-2009-1048CVE
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 …
2009-01-01Pre-auth
EPSS6.4%
pct 92
4.3
CVE-2018-8383MSR
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "…
2018-01-01MicrosoftPre-auth
EPSS6.2%
pct 92
5.8
CVE-2013-2172DEB
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for J…
2013-01-01
EPSS5.9%
pct 92
5.3
CVE-2015-8139DEB
ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then imperso…
2015-01-01Pre-auth
EPSS5.8%
pct 92
9.8
CVE-2019-16871CVE
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering …
2019-01-01Pre-auth
EPSS5.3%
pct 91
6.5
CVE-2021-21134AST
Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remo…
2021-01-01Pre-auth
EPSS5.0%
pct 91
6.5
CVE-2020-26144MSR
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 …
2020-01-01Microsoft
EPSS4.9%
pct 90
4.0
CVE-2020-25686AST
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check…
2020-01-01Pre-auth
EPSS4.9%
pct 90
7.5
CVE-2021-41753CVE
A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in D-Link DIR-X1560, v1…
2021-01-01Pre-auth
EPSS4.8%
pct 90
9.8
CVE-2017-14375CVE
EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabl…
2017-01-01Pre-auth
EPSS4.8%
pct 90
8.2
CVE-2025-32966ANC
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticat…
2025-01-01Pre-auth
EPSS3.9%
pct 88
4.3
CVE-2013-6483DEB
The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine wheth…
2013-01-01
EPSS3.9%
pct 88
6.5
CVE-2017-6062DEB
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module …
2017-01-01Pre-auth
EPSS3.6%
pct 88
Select a vulnerability on the left to open the preview.