All vulnerabilities
932 / 932
Sort
7.5
CVE-2020-13935DEB
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 …
2020-01-01Pre-auth
EPSS87.6%
pct 99
7.5
CVE-2020-36227AST
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the c…
2020-01-01Pre-auth
EPSS77.7%
pct 99
7.5
CVE-2022-0778AST
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause…
2022-01-01Pre-auth
EPSS70.6%
pct 99
7.5
CVE-2019-14241DEB
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors rela…
2019-01-01Pre-auth
EPSS70.2%
pct 99
7.5
CVE-2017-16944DEB
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote at…
2017-01-01Pre-auth
EPSS63.3%
pct 99
8.6
CVE-2024-20353CVE KEV
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (AS…
2024-01-01KEV
EPSS63.3%
pct 99
7.5
CVE-2023-34966AST
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When pars…
2023-01-01Pre-auth
EPSS62.0%
pct 99
6.5
CVE-2019-0190AST
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a c…
2019-01-01Pre-auth
EPSS59.9%
pct 99
7.5
CVE-2020-7046DEB
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-…
2020-01-01Pre-auth
EPSS50.4%
pct 98
7.5
CVE-2021-4044DEB
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificat…
2021-01-01Pre-auth
EPSS50.1%
pct 98
7.5
CVE-2022-23833AST
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and …
2022-01-01Pre-auth
EPSS49.2%
pct 98
7.5
CVE-2019-5097CVE
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in …
2019-01-01Pre-auth
EPSS45.1%
pct 98
7.5
CVE-2024-50320CVE
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to c…
2024-01-01Pre-auth
EPSS31.2%
pct 98
5.9
CVE-2016-4008DEB
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used wi…
2016-01-01Pre-auth
EPSS29.6%
pct 97
3.3
CVE-2011-1002DEB
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a d…
2011-01-01
EPSS29.4%
pct 97
3.7
CVE-2017-3140DEB
If named is configured to use Response Policy Zones (RPZ) an error processing some rule types c…
2017-01-01Pre-auth
EPSS25.5%
pct 97
7.5
CVE-2023-1718CVE
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.3…
2023-01-01Pre-auth
EPSS24.1%
pct 97
7.5
CVE-2017-15908DEB
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC reso…
2017-01-01Pre-auth
EPSS23.6%
pct 97
4.3
CVE-2015-1788DEB
The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.…
2015-01-01
EPSS23.2%
pct 97
7.5
CVE-2023-45363DEB
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x be…
2023-01-01Pre-auth
EPSS22.7%
pct 97
4.3
CVE-2015-1792DEB
The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0…
2015-01-01
EPSS22.5%
pct 97
5.0
CVE-2004-0748DEB
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU …
2004-01-01
EPSS22.3%
pct 97
7.5
CVE-2022-46770CVE
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS use…
2022-01-01Pre-auth
EPSS21.5%
pct 97
4.3
CVE-2014-0238DEB
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and…
2014-01-01
EPSS20.8%
pct 97
7.5
CVE-2018-1336DEB
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to …
2018-01-01Pre-auth
EPSS20.6%
pct 97
7.5
CVE-2019-18217DEB
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-servi…
2019-01-01Pre-auth
EPSS19.5%
pct 97
5.0
CVE-2005-2224CVE
aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of se…
2005-01-01
EPSS17.8%
pct 96
7.5
CVE-2022-0711AST
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" heade…
2022-01-01Pre-auth
EPSS16.2%
pct 96
5.0
CVE-2009-1890DEB
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP S…
2009-01-01
EPSS16.2%
pct 96
7.5
CVE-2019-12402DEB
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can ge…
2019-01-01Pre-auth
EPSS16.2%
pct 96
4.3
CVE-2018-1041DEB
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting version…
2018-01-01
EPSS16.1%
pct 96
5.9
CVE-2016-6305DEB
The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows rem…
2016-01-01Pre-auth
EPSS16.0%
pct 96
7.5
CVE-2019-3833DEB
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_conne…
2019-01-01Pre-auth
EPSS15.2%
pct 96
4.3
CVE-2018-5711AST
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before …
2018-01-01Pre-auth
EPSS13.4%
pct 95
3.3
CVE-2017-8871AST
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote atta…
2017-01-01
EPSS13.0%
pct 95
7.5
CVE-2021-35515DEB
When reading a specially crafted 7Z archive, the construction of the list of codecs that decomp…
2021-01-01Pre-auth
EPSS11.9%
pct 95
6.5
CVE-2021-3737AST
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of pyth…
2021-01-01Pre-auth
EPSS11.6%
pct 95
7.5
CVE-2024-33623CVE
A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6…
2024-01-01Pre-auth
EPSS11.4%
pct 95
3.7
CVE-2016-4970DEB
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final …
2016-01-01Pre-auth
EPSS11.3%
pct 95
7.5
CVE-2018-10546AST
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2…
2018-01-01Pre-auth
EPSS10.6%
pct 95
Select a vulnerability on the left to open the preview.