All vulnerabilities
528 / 528
Sort
7.5
CVE-2024-29059MSR KEV
.NET Framework Information Disclosure Vulnerability
2024-01-01MicrosoftKEV
EPSS98.8%
pct 99
6.4
CVE-2010-3332CVE
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for AS…
2010-01-01
EPSS67.5%
pct 99
7.5
CVE-2025-62168ANC
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP …
2025-01-01Pre-auth
EPSS63.3%
pct 99
6.5
CVE-2013-7331CVE KEV
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attacke…
2013-01-01KEV
EPSS58.0%
pct 98
4.3
CVE-2025-47813CVE KEV
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the …
2025-01-01KEV
EPSS56.4%
pct 98
5.3
CVE-2021-30357CVE
SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of th…
2021-01-01Pre-auth
EPSS22.8%
pct 97
5.3
CVE-2021-31159CVE
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due…
2021-01-01Pre-auth
EPSS17.8%
pct 96
5.3
CVE-2020-11883CVE
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in Vu…
2020-01-01Pre-auth
EPSS15.2%
pct 96
3.5
CVE-2012-5615DEB
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.6…
2012-01-01
EPSS14.8%
pct 96
5.3
CVE-2024-21733DEB
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.Thi…
2024-01-01Pre-auth
EPSS14.3%
pct 96
7.5
CVE-2018-17961AST
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism …
2018-01-01Pre-auth
EPSS10.0%
pct 94
5.3
CVE-2024-45440DEB
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is N…
2024-01-01Pre-auth
EPSS9.3%
pct 94
7.5
CVE-2022-29266CVE
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's …
2022-01-01Pre-auth
EPSS7.7%
pct 93
7.5
CVE-2022-0660CVE
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber…
2022-01-01Pre-auth
EPSS6.9%
pct 93
6.5
CVE-2023-20593AST
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacke…
2023-01-01
EPSS5.8%
pct 92
5.3
CVE-2018-6188AST
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9,…
2018-01-01Pre-auth
EPSS4.9%
pct 90
7.5
CVE-2020-15478CVE
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
2020-01-01Pre-auth
EPSS4.7%
pct 90
3.7
CVE-2018-12536DEB
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, wh…
2018-01-01Pre-auth
EPSS4.3%
pct 89
7.5
CVE-2021-22885AST
A possible information disclosure / unintended method execution vulnerability in Action Pack >=…
2021-01-01Pre-auth
EPSS4.2%
pct 89
7.5
CVE-2024-39719DEB
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/c…
2024-01-01Pre-auth
EPSS4.1%
pct 89
7.5
CVE-2015-3167DEB
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x b…
2015-01-01Pre-auth
EPSS4.0%
pct 89
6.5
CVE-2023-27587CVE
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an …
2023-01-01
EPSS3.9%
pct 88
9.8
CVE-2018-11325CVE
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofil…
2018-01-01Pre-auth
EPSS3.8%
pct 88
7.5
CVE-2026-29146ANC
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
…
2026-01-01Pre-auth
EPSS3.6%
pct 88
7.5
CVE-2019-7941CVE
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure T…
2019-01-01Pre-auth
EPSS3.1%
pct 86
5.0
CVE-2000-1191CVE
htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determ…
2000-01-01
EPSS3.0%
pct 85
4.0
CVE-2013-0212DEB
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly…
2013-01-01
EPSS3.0%
pct 85
5.0
CVE-2014-2064DEB
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins b…
2014-01-01
EPSS3.0%
pct 85
7.5
CVE-2019-4269CVE
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote atta…
2019-01-01Pre-auth
EPSS2.7%
pct 84
7.5
CVE-2021-25958CVE
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle erro…
2021-01-01Pre-auth
EPSS2.6%
pct 83
4.3
CVE-2014-8161DEB
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4…
2014-01-01
EPSS2.5%
pct 82
5.3
CVE-2024-44762DEB
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows atta…
2024-01-01Pre-auth
EPSS2.5%
pct 82
4.3
CVE-2016-4992DEB
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux …
2016-01-01
EPSS2.4%
pct 81
9.8
CVE-2019-7612DEB
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1…
2019-01-01Pre-auth
EPSS2.4%
pct 81
7.5
CVE-2014-1487DEB
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Th…
2014-01-01Pre-auth
EPSS2.3%
pct 81
8.8
CVE-2024-28939MSR
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
2024-01-01MicrosoftPre-auth
EPSS2.3%
pct 80
6.8
CVE-2018-12886DEB
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler …
2018-01-01
EPSS2.2%
pct 79
3.5
CVE-2018-10913DEB
An information disclosure vulnerability was discovered in glusterfs server. An attacker could i…
2018-01-01
EPSS2.1%
pct 79
5.3
CVE-2021-46353CVE
An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remot…
2021-01-01Pre-auth
EPSS2.1%
pct 79
7.5
CVE-2021-29688CVE
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive informati…
2021-01-01Pre-auth
EPSS2.0%
pct 78
Select a vulnerability on the left to open the preview.