Skip to content
English

Priority list

What to patch first

The vulnerabilities in CISA’s catalog of exploited vulnerabilities, in the recommended order of remediation.

Edit

1,729 vulnerabilities across all products. To see only yours: Choose my products.

How the list is ranked

  1. Recent additions first to the catalog of exploited vulnerabilities (August 30, 2026 to September 28, 2026), newest to oldest: these are the most current attacks.
  2. Then this year’s additions (between 31 days and one year old), from most to least severe by CVSS score (0 to 10); for equal scores, the most recently added first.
  3. Finally, all the others, older, from most to least severe.

Within each group, vulnerabilities without a published score come last. End-of-life products, which no patch will ever fix, are listed separately after the list.

What should I do? Check whether you use the product, then follow the required action on its page: most of the time, apply the vendor’s patch. The rule in detail.

The patch list

  1. Rank 1Citrix NetScaler ADC / Gateway

    CVE-2026-88771

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    Citrix NetScaler Improper Input Validation Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Citrix NetScaler ADC / Gateway

    CVE-2026-88772

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 27, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  3. Rank 3Microsoft SharePoint Server

    CVE-2026-65660

    Recently addedHunt for compromise (CISA)

    Microsoft SharePoint Code Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  4. Rank 4WordPress Core

    CVE-2026-87902

    Recently addedHunt for compromise (CISA)

    WordPress Core Remote File Inclusion Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  5. Rank 5MikroTik RouterOS

    CVE-2026-67279

    Recently added

    Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 25, 2026
    CISA deadline
    3 days
    CVSS severity
    6.5 (medium)
  6. Rank 6WSO2 API Manager, Identity Server, Integrator

    CVE-2026-5430

    Recently addedHunt for compromise (CISA)

    WSO2 Multiple Products Path Traversal Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 24, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  7. Rank 7Adobe Commerce (Magento)

    CVE-2026-71362

    Recently addedHunt for compromise (CISA)

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 24, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  8. Rank 8Arista SD-WAN (VeloCloud)

    CVE-2026-93952

    Recently addedHunt for compromise (CISA)

    Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  9. Rank 9Check Point Quantum Security Gateway

    CVE-2026-85102

    Recently addedHunt for compromise (CISA)

    Check Point Multiple Products Improper Certificate Validation Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Check Point Security Management / SmartConsole

    CVE-2026-93616

    Recently addedHunt for compromise (CISA)

    Check Point Multiple Products Path Traversal Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
Show the other 1,647 vulnerabilities in the list
  1. Rank 11F5 BIG-IP

    CVE-2026-94127

    Recently addedHunt for compromise (CISA)

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Zyxel Switches (GS, XGS)

    CVE-2026-7273

    Recently addedHunt for compromise (CISA)

    Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 21, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  3. Rank 13Linux Kernel

    CVE-2025-39682

    Recently addedHunt for compromise (CISA)

    Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Linux Kernel

    CVE-2026-53266

    Recently addedHunt for compromise (CISA)

    Linux Kernel Out-of-Bounds Write Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 18, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  5. Rank 15Linux Kernel

    CVE-2025-39964

    Recently addedHunt for compromise (CISA)

    Linux Kernel Race Condition Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 18, 2026
    CISA deadline
    3 days
    CVSS severity
    5.5 (medium)
  6. Rank 16Cisco Identity Services Engine (ISE)

    CVE-2026-76460

    Recently addedHunt for compromise (CISA)

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 16, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  7. Rank 17Google Pixel

    CVE-2026-58704

    Recently addedHunt for compromise (CISA)

    Google Pixel Improper Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 16, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  8. Rank 18Acronis Backup

    CVE-2026-87886

    Recently addedHunt for compromise (CISA)

    Acronis Backup Incorrect Default Permissions Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 16, 2026
    CISA deadline
    3 days
    CVSS severity
    7.8 (high)
  9. Rank 19Cisco Secure Email Gateway

    CVE-2026-76461

    Recently addedHunt for compromise (CISA)

    Cisco Secure Email Gateway SQL Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 14, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  10. Rank 20GitLab Community / Enterprise Edition (CE/EE)

    CVE-2026-85706

    Recently addedHunt for compromise (CISA)

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  11. Rank 21ConnectWise ScreenConnect

    CVE-2026-84869

    Recently addedHunt for compromise (CISA)

    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    3 days
    CVSS severity
    9.9 (critical)
  12. Rank 22JFrog Artifactory

    CVE-2026-42016

    Recently added

    JFrog Artifactory Incorrect Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  13. Rank 23JFrog Artifactory

    CVE-2026-42018

    Recently added

    JFrog Artifactory Improper Authentication Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  14. Rank 24MikroTik RouterOS

    CVE-2026-86060

    Recently addedHunt for compromise (CISA)

    MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 10, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  15. Rank 25MikroTik RouterOS

    CVE-2026-67277

    Recently added

    MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 10, 2026
    CISA deadline
    3 days
    CVSS severity
    8.2 (high)
  16. Rank 26Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20079

    Recently addedHunt for compromise (CISA)

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  17. Rank 27Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-25249

    Recently addedHunt for compromise (CISA)

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Citrix NetScaler ADC / Gateway

    CVE-2026-19490

    Recently addedHunt for compromise (CISA)

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Google Chrome / Chromium

    CVE-2026-87491

    Recently added

    Google Chromium V8 Out of Bounds Write Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  20. Rank 30Adobe Commerce (Magento)

    CVE-2026-75650

    Recently addedHunt for compromise (CISA)

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  21. Rank 31N-able N-central

    CVE-2026-86218

    Recently addedHunt for compromise (CISA)

    N-able N-central Static Code Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Microsoft Windows

    CVE-2026-81963

    Recently added

    Microsoft Windows Link Following Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  23. Rank 33Microsoft Windows

    CVE-2026-85880

    Recently added

    Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  24. Rank 34Google Chrome / Chromium

    CVE-2026-85046

    Recently added

    Google Chromium V8 Type Confusion Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 4, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  25. Rank 35Kestra OSS

    CVE-2026-49869

    Recently addedHunt for compromise (CISA)

    Kestra OSS OS Command Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  26. Rank 36SonicWall SMA 1000

    CVE-2026-83548

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  27. Rank 37JFrog Artifactory

    CVE-2026-82329

    Recently addedHunt for compromise (CISA)

    JFrog Artifactory Improper Authentication Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  28. Rank 38Sangoma Switchvox

    CVE-2026-9586

    Recently addedHunt for compromise (CISA)

    Sangoma Switchvox SQL Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  29. Rank 39BerriAI LiteLLM

    CVE-2026-59822

    Recently added

    BerriAI LiteLLM Improper Authentication Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    14 days
    CVSS severity
    8.2 (high)
  30. Rank 40SonicWall SMA 1000

    CVE-2026-83549

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    SonicWall SMA1000 Appliances OS Command Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    7.8 (high)
  31. Rank 41Starlette

    CVE-2026-48710

    Recently added

    Kludex Starlette HTTP Request/Response Smuggling Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  32. Rank 42PaperCut NG / MF

    CVE-2026-81578

    Recently added

    PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Aug 31, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  33. Rank 43PaperCut NG / MF

    CVE-2026-82078

    Recently added

    PaperCut NG/MF Unsafe Reflection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Aug 31, 2026
    CISA deadline
    14 days
    CVSS severity
    9.1 (critical)
  34. Rank 44Oracle WebLogic Server

    CVE-2026-21962

    Hunt for compromise (CISA)

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 24, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  35. Rank 45Metabase

    CVE-2026-72898

    Active CERT-FR alertHunt for compromise (CISA)

    Metabase SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 11, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  36. Rank 46Arista SD-WAN (VeloCloud)

    CVE-2026-16812

    Hunt for compromise (CISA)

    Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 27, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  37. Rank 47SonicWall SMA 1000

    CVE-2026-15409

    Hunt for compromise (CISA)Ransomware

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  38. Rank 48Adobe ColdFusion

    CVE-2026-48282

    Hunt for compromise (CISA)

    Adobe ColdFusion Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  39. Rank 49SimpleHelp

    CVE-2026-48558

    SimpleHelp Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 29, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  40. Rank 50Ubiquiti UniFi OS / UniFi Network

    CVE-2026-34908

    Ubiquiti UniFi OS Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  41. Rank 51Ubiquiti UniFi OS / UniFi Network

    CVE-2026-34909

    Ubiquiti UniFi OS Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  42. Rank 52Ubiquiti UniFi OS / UniFi Network

    CVE-2026-34910

    Ubiquiti UniFi OS Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  43. Rank 53Ivanti Sentry

    CVE-2026-10520

    Ivanti Sentry OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 11, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  44. Rank 54Cisco Catalyst SD-WAN

    CVE-2026-20182

    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 14, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  45. Rank 55Quest KACE Systems Management Appliance (SMA)

    CVE-2025-32975

    Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  46. Rank 56Craft CMS

    CVE-2025-32432

    Craft CMS Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 20, 2026
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  47. Rank 57Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20131

    Ransomware

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 19, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  48. Rank 58Cisco Catalyst SD-WAN

    CVE-2026-20127

    Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 25, 2026
    CISA deadline
    2 days
    CVSS severity
    10.0 (critical)
  49. Rank 59Dell RecoverPoint

    CVE-2026-22769

    Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 18, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  50. Rank 60SmarterTools SmarterMail

    CVE-2025-52691

    Ransomware

    SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  51. Rank 61Cisco Secure Email Gateway

    CVE-2025-20393

    Cisco Multiple Products Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  52. Rank 62React (Meta) React Server Components

    CVE-2025-55182

    Ransomware

    Meta React Server Components Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 5, 2025
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  53. Rank 63Adobe Experience Manager (AEM)

    CVE-2025-54253

    Adobe Experience Manager Forms Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 15, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  54. Rank 64SimpleHelp

    CVE-2024-57726

    RansomwareCVE from 2024, added in 2026

    SimpleHelp Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    9.9 (critical)
  55. Rank 65ownCloud Server

    CVE-2023-49105

    Hunt for compromise (CISA)CVE from 2023, added in 2026

    ownCloud Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  56. Rank 66Ajax.NET Professional

    CVE-2021-23758

    CVE from 2021, added in 2026

    Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  57. Rank 67Citrix NetScaler ADC / Gateway

    CVE-2026-8452

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  58. Rank 68Gitea

    CVE-2026-60004

    Hunt for compromise (CISA)

    Gitea Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 25, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  59. Rank 69TrueConf Server

    CVE-2026-72529

    Hunt for compromise (CISA)

    TrueConf Server Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 20, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  60. Rank 70Microsoft Windows

    CVE-2026-33824

    Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  61. Rank 71VMware (Broadcom) vCenter Server

    CVE-2026-59310

    Hunt for compromise (CISA)Ransomware

    Broadcom VMware vCenter Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  62. Rank 72Apple macOS (OS X)

    CVE-2026-65400

    Hunt for compromise (CISA)

    Apple macOS Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  63. Rank 73Progress Kemp LoadMaster

    CVE-2026-8037

    Hunt for compromise (CISA)

    Progress LoadMaster Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 7, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  64. Rank 74JetBrains TeamCity

    CVE-2026-63077

    Hunt for compromise (CISA)Ransomware

    JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 5, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  65. Rank 75Langflow

    CVE-2026-9198

    Hunt for compromise (CISA)

    IBM Langflow Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 4, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  66. Rank 76Check Point Security Management / SmartConsole

    CVE-2026-16232

    Hunt for compromise (CISA)

    Check Point SmartConsole Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  67. Rank 77Microsoft SharePoint Server

    CVE-2026-50522

    Hunt for compromise (CISA)

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  68. Rank 78Langflow

    CVE-2026-0770

    Hunt for compromise (CISA)

    Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 21, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  69. Rank 79WordPress Core

    CVE-2026-63030

    Hunt for compromise (CISA)

    WordPress Core Interpretation Conflict Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 21, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  70. Rank 80Fortinet FortiSandbox

    CVE-2026-25089

    Hunt for compromise (CISA)

    Fortinet FortiSandbox OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  71. Rank 81Fortinet FortiSandbox

    CVE-2026-39808

    Hunt for compromise (CISA)

    Fortinet FortiSandbox OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  72. Rank 82Microsoft SharePoint Server

    CVE-2026-58644

    Hunt for compromise (CISA)

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  73. Rank 83Oracle E-Business Suite

    CVE-2026-46817

    Hunt for compromise (CISA)

    Oracle E-Business Suite Improper Privilege Management Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 15, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  74. Rank 84Microsoft SharePoint Server

    CVE-2026-56164

    Hunt for compromise (CISA)

    Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  75. Rank 85iCagenda

    CVE-2026-48939

    Hunt for compromise (CISA)

    iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 10, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  76. Rank 86Balbooa Forms

    CVE-2026-56291

    Hunt for compromise (CISA)

    Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 10, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  77. Rank 87JoomShaper SP Page Builder

    CVE-2026-48908

    Hunt for compromise (CISA)

    JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  78. Rank 88Joomlack Page Builder

    CVE-2026-56290

    Hunt for compromise (CISA)

    Joomlack Page Builder Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  79. Rank 89PTC Windchill and FlexPLM

    CVE-2026-12569

    Ransomware

    PTC Windchill and FlexPLM Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 25, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  80. Rank 90Lantronix EDS5000

    CVE-2025-67038

    Lantronix EDS5000 Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  81. Rank 91Splunk Enterprise

    CVE-2026-20253

    Splunk Enterprise Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  82. Rank 92Widget Factory (JCE) JCE (Joomla Content Editor)

    CVE-2026-48907

    Widget Factory Joomla Content Editor Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  83. Rank 93Oracle PeopleSoft

    CVE-2026-35273

    Ransomware

    Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 12, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  84. Rank 94Mirasvit Full Page Cache Warmer

    CVE-2026-45247

    Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 3, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  85. Rank 95Nx Console

    CVE-2026-48027

    Ransomware

    Nx Console Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 27, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  86. Rank 96DAEMON Tools Lite

    CVE-2026-8398

    Daemon Tools Lite Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  87. Rank 97LiteSpeed cPanel Plugin

    CVE-2026-48172

    LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 26, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  88. Rank 98Drupal Core

    CVE-2026-9082

    Drupal Core SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 22, 2026
    CISA deadline
    5 days
    CVSS severity
    9.8 (critical)
  89. Rank 99Microsoft Windows

    CVE-2008-4250

    CVE from 2008, added in 2026

    Microsoft Windows Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  90. Rank 100BerriAI LiteLLM

    CVE-2026-42208

    BerriAI LiteLLM SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  91. Rank 101Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2026-0300

    Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 6, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  92. Rank 102cPanel (WebPros) cPanel & WHM (WP Squared)

    CVE-2026-41940

    Ransomware

    WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 30, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  93. Rank 103Samsung MagicINFO Server

    CVE-2024-7399

    CVE from 2024, added in 2026

    Samsung MagicINFO 9 Server Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  94. Rank 104Marimo

    CVE-2026-39987

    Marimo Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 23, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  95. Rank 105Fortinet FortiClient EMS

    CVE-2026-21643

    Fortinet FortiClient EMS SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  96. Rank 106Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-1340

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  97. Rank 107Fortinet FortiClient EMS

    CVE-2026-35616

    Fortinet FortiClient EMS Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 6, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  98. Rank 108Citrix NetScaler ADC / Gateway

    CVE-2026-3055

    Citrix NetScaler Out-of-Bounds Read Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 30, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  99. Rank 109F5 BIG-IP

    CVE-2025-53521

    F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  100. Rank 110Langflow

    CVE-2026-33017

    Langflow Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 25, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  101. Rank 111Laravel Livewire

    CVE-2025-54068

    Laravel Livewire Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 20, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  102. Rank 112Microsoft SharePoint Server

    CVE-2026-20963

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  103. Rank 113SolarWinds Web Help Desk

    CVE-2025-26399

    Ransomware

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  104. Rank 114Hikvision IP cameras and recorders (NVR/DVR)

    CVE-2017-7921

    CVE from 2017, added in 2026

    Hikvision Multiple Products Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  105. Rank 115Rockwell Automation Logix (PLCs, Studio 5000)

    CVE-2021-22681

    CVE from 2021, added in 2026

    Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  106. Rank 116GitLab Community / Enterprise Edition (CE/EE)

    CVE-2021-22175

    CVE from 2021, added in 2026

    GitLab Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 18, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  107. Rank 117Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2020-7796

    CVE from 2020, added in 2026

    Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  108. Rank 118BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2026-1731

    Ransomware

    BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 13, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  109. Rank 119Microsoft Configuration Manager

    CVE-2024-43468

    CVE from 2024, added in 2026

    Microsoft Configuration Manager SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  110. Rank 120SolarWinds Web Help Desk

    CVE-2025-40536

    SolarWinds Web Help Desk Security Control Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  111. Rank 121React Native Community React Native CLI

    CVE-2025-11953

    React Native Community CLI OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  112. Rank 122SmarterTools SmarterMail

    CVE-2026-24423

    Ransomware

    SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  113. Rank 123Sangoma FreePBX

    CVE-2019-19006

    CVE from 2019, added in 2026

    Sangoma FreePBX Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  114. Rank 124SolarWinds Web Help Desk

    CVE-2025-40551

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  115. Rank 125Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-1281

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 29, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  116. Rank 126Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2026-24858

    Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  117. Rank 127SmarterTools SmarterMail

    CVE-2026-23760

    Ransomware

    SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  118. Rank 128GNU InetUtils

    CVE-2026-24061

    GNU InetUtils Argument Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  119. Rank 129VMware (Broadcom) vCenter Server

    CVE-2024-37079

    CVE from 2024, added in 2026

    Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 23, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  120. Rank 130Cisco Unified Communications Manager

    CVE-2026-20045

    Cisco Unified Communications Products Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 21, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  121. Rank 131HPE OneView

    CVE-2025-37164

    Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 7, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  122. Rank 132WatchGuard Firebox / XTM (Fireware)

    CVE-2025-14733

    Ransomware

    WatchGuard Firebox Out of Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 19, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  123. Rank 133ASUS Live Update

    CVE-2025-59374

    ASUS Live Update Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  124. Rank 134Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-59718

    Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 16, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  125. Rank 135Gladinet CentreStack / Triofox

    CVE-2025-14611

    Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 15, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  126. Rank 136OSGeo GeoServer

    CVE-2025-58360

    OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 11, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  127. Rank 137D-Link Routers (DIR, DWR, DSR)

    CVE-2022-37055

    CVE from 2022, added in 2025

    D-Link Routers Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 8, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  128. Rank 138Array Networks ArrayOS AG / vxAG

    CVE-2025-66644

    Array Networks ArrayOS AG OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 8, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  129. Rank 139Oracle Identity and Access Management (OIM / OAM)

    CVE-2025-61757

    Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 21, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  130. Rank 140Fortinet FortiWeb

    CVE-2025-64446

    Fortinet FortiWeb Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 14, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  131. Rank 141WatchGuard Firebox / XTM (Fireware)

    CVE-2025-9242

    WatchGuard Firebox Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 12, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  132. Rank 142Samsung Mobile Devices (Galaxy)

    CVE-2025-21042

    Samsung Mobile Devices Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 10, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  133. Rank 143XWiki Platform

    CVE-2025-24893

    XWiki Platform Eval Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 30, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  134. Rank 144Microsoft Windows

    CVE-2025-59287

    Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  135. Rank 145Motex LANSCOPE Endpoint Manager

    CVE-2025-61932

    Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  136. Rank 146Kentico Xperience

    CVE-2025-2746

    Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  137. Rank 147Kentico Xperience

    CVE-2025-2747

    Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  138. Rank 148SKYSEA Client View

    CVE-2016-7836

    CVE from 2016, added in 2025

    SKYSEA Client View Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 14, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  139. Rank 149Mozilla Firefox

    CVE-2010-3765

    CVE from 2010, added in 2025

    Mozilla Multiple Products Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  140. Rank 150Oracle E-Business Suite

    CVE-2025-61882

    Ransomware

    Oracle E-Business Suite Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  141. Rank 151Juniper ScreenOS (NetScreen)

    CVE-2015-7755

    CVE from 2015, added in 2025

    Juniper ScreenOS Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  142. Rank 152Jenkins Core

    CVE-2017-1000353

    CVE from 2017, added in 2025

    Jenkins Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  143. Rank 153Samsung Mobile Devices (Galaxy)

    CVE-2025-21043

    Samsung Mobile Devices Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  144. Rank 154Fortra GoAnywhere MFT

    CVE-2025-10035

    Ransomware

    Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  145. Rank 155TanStack

    CVE-2026-45321

    Ransomware

    TanStack Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 27, 2026
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  146. Rank 156MLflow

    CVE-2026-64849

    MLflow Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 19, 2026
    CISA deadline
    14 days
    CVSS severity
    9.3 (critical)
  147. Rank 157Check Point Quantum Security Gateway

    CVE-2026-50751

    Ransomware

    Check Point Security Gateway Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.3 (critical)
  148. Rank 158Microsoft SharePoint Server

    CVE-2026-55040

    Hunt for compromise (CISA)

    Microsoft SharePoint Weak Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  149. Rank 159Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2026-0257

    Ransomware

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 29, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  150. Rank 160Gladinet CentreStack / Triofox

    CVE-2025-12480

    Gladinet Triofox Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 12, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  151. Rank 161Dassault Systèmes DELMIA Apriso

    CVE-2025-6205

    Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 28, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  152. Rank 162Adobe Commerce (Magento)

    CVE-2025-54236

    Adobe Commerce and Magento Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  153. Rank 163TrueConf Server

    CVE-2026-72530

    TrueConf Server Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 20, 2026
    CISA deadline
    14 days
    CVSS severity
    9.0 (critical)
  154. Rank 164CWP (Control Web Panel / CentOS Web Panel) Control Web Panel

    CVE-2025-48703

    CWP Control Web Panel OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 4, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  155. Rank 165Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2026-73570

    Hunt for compromise (CISA)

    Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 21, 2026
    CISA deadline
    3 days
    CVSS severity
    8.9 (high)
  156. Rank 166Microsoft SQL Server

    CVE-2019-1068

    Hunt for compromise (CISA)CVE from 2019, added in 2026

    Microsoft SQL Server Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  157. Rank 167Ray

    CVE-2025-62593

    Hunt for compromise (CISA)

    Ray-Project Ray Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 17, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  158. Rank 168Microsoft SharePoint Server

    CVE-2026-45659

    Hunt for compromise (CISA)Ransomware

    Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 1, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  159. Rank 169Google Chrome / Chromium

    CVE-2026-11645

    Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 9, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  160. Rank 170BerriAI LiteLLM

    CVE-2026-42271

    BerriAI LiteLLM Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 8, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  161. Rank 171Langflow

    CVE-2025-34291

    Langflow Origin Validation Error Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 21, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  162. Rank 172Microsoft Windows

    CVE-2009-1537

    CVE from 2009, added in 2026

    Microsoft DirectX NULL Byte Overwrite Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  163. Rank 173Adobe Acrobat / Reader

    CVE-2009-3459

    CVE from 2009, added in 2026

    Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  164. Rank 174Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-0249

    CVE from 2010, added in 2026

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  165. Rank 175Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-0806

    CVE from 2010, added in 2026

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  166. Rank 176Apache ActiveMQ

    CVE-2026-34197

    Apache ActiveMQ Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 16, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  167. Rank 177Microsoft Office

    CVE-2009-0238

    CVE from 2009, added in 2026

    Microsoft Office Remote Code Execution

    Added in the last 12 months: ranked by severity.

    Added
    Apr 14, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  168. Rank 178Microsoft Exchange Server

    CVE-2023-21529

    RansomwareCVE from 2023, added in 2026

    Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  169. Rank 179Google Chrome / Chromium

    CVE-2026-5281

    Google Dawn Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 1, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  170. Rank 180Aqua Security Trivy

    CVE-2026-33634

    Aquasecurity Trivy Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 26, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  171. Rank 181Apple Safari / WebKit

    CVE-2025-31277

    Apple Multiple Products Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  172. Rank 182Google Chrome / Chromium

    CVE-2026-3909

    Google Skia Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  173. Rank 183Google Chrome / Chromium

    CVE-2026-3910

    Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  174. Rank 184n8n

    CVE-2025-68613

    n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 11, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  175. Rank 185Apple Safari / WebKit

    CVE-2023-43000

    CVE from 2023, added in 2026

    Apple Multiple products Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  176. Rank 186Soliton Systems FileZen

    CVE-2026-25108

    Soliton Systems K.K FileZen OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 24, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  177. Rank 187Roundcube Webmail

    CVE-2025-49113

    RoundCube Webmail Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 20, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  178. Rank 188Microsoft Windows

    CVE-2008-0015

    CVE from 2008, added in 2026

    Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  179. Rank 189Google Chrome / Chromium

    CVE-2026-2441

    Google Chromium CSS Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  180. Rank 190Microsoft Windows

    CVE-2026-21510

    Microsoft Windows Shell Protection Mechanism Failure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  181. Rank 191Microsoft Windows

    CVE-2026-21513

    Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  182. Rank 192Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-68645

    Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  183. Rank 193Gogs

    CVE-2025-8110

    Gogs Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 12, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  184. Rank 194Microsoft Office

    CVE-2009-0556

    CVE from 2009, added in 2026

    Microsoft Office PowerPoint Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 7, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  185. Rank 195Digiever DS-2105 Pro

    CVE-2023-52163

    CVE from 2023, added in 2025

    Digiever DS-2105 Pro Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 22, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  186. Rank 196Apple Safari / WebKit

    CVE-2025-43529

    Apple Multiple Products Use-After-Free WebKit Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 15, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  187. Rank 197Sierra Wireless AirLink ALEOS

    CVE-2018-4063

    CVE from 2018, added in 2025

    Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  188. Rank 198Google Chrome / Chromium

    CVE-2025-14174

    Google Chromium Out of Bounds Memory Access Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  189. Rank 199OpenPLC ScadaBR

    CVE-2021-26828

    CVE from 2021, added in 2025

    OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 3, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  190. Rank 200Google Chrome / Chromium

    CVE-2025-13223

    Google Chromium V8 Type Confusion Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  191. Rank 201Apple Safari / WebKit

    CVE-2022-48503

    CVE from 2022, added in 2025

    Apple Multiple Products Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  192. Rank 202Microsoft Windows

    CVE-2025-33073

    Microsoft Windows SMB Client Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  193. Rank 203Microsoft Windows

    CVE-2011-3402

    CVE from 2011, added in 2025

    Microsoft Windows Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  194. Rank 204Microsoft Windows

    CVE-2013-3918

    CVE from 2013, added in 2025

    Microsoft Windows Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  195. Rank 205GNU Bash

    CVE-2014-6278

    CVE from 2014, added in 2025

    GNU Bash OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  196. Rank 206Smartbedded Meteobridge

    CVE-2025-4008

    Smartbedded Meteobridge Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  197. Rank 207Cisco ASA / Firepower (FTD)

    CVE-2026-20349

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 11, 2026
    CISA deadline
    3 days
    CVSS severity
    8.6 (high)
  198. Rank 208Cisco Unified Communications Manager

    CVE-2026-20230

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.6 (high)
  199. Rank 209Adobe Acrobat / Reader

    CVE-2026-34621

    Adobe Acrobat and Reader Prototype Pollution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  200. Rank 210LiteSpeed cPanel Plugin

    CVE-2026-54420

    LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 15, 2026
    CISA deadline
    3 days
    CVSS severity
    8.5 (high)
  201. Rank 211Langflow

    CVE-2026-55255

    Hunt for compromise (CISA)

    Langflow Authorization Bypass Through User-Controlled Key Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    8.4 (high)
  202. Rank 212Google Android

    CVE-2025-48595

    Android Framework Integer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 2, 2026
    CISA deadline
    3 days
    CVSS severity
    8.4 (high)
  203. Rank 213ConnectWise ScreenConnect

    CVE-2024-1708

    RansomwareCVE from 2024, added in 2026

    ConnectWise ScreenConnect Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 28, 2026
    CISA deadline
    14 days
    CVSS severity
    8.4 (high)
  204. Rank 214N-able N-central

    CVE-2026-18577

    Hunt for compromise (CISA)

    N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 3, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  205. Rank 215DD-WRT

    CVE-2021-27137

    Hunt for compromise (CISA)CVE from 2021, added in 2026

    DD-WRT Stack-Based Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 21, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  206. Rank 216Cisco IOS / IOS XE

    CVE-2008-4128

    Hunt for compromise (CISA)CVE from 2008, added in 2026

    Cisco IOS Cross-Site Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 13, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  207. Rank 217VMware (Broadcom) Aria Operations (ex-vRealize Operations)

    CVE-2026-22719

    Broadcom VMware Aria Operations Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 3, 2026
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  208. Rank 218Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-3962

    CVE from 2010, added in 2025

    Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  209. Rank 219Dassault Systèmes DELMIA Apriso

    CVE-2025-6204

    Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 28, 2025
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  210. Rank 220Linux Kernel

    CVE-2026-53362

    Hunt for compromise (CISA)

    Linux Kernel Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 27, 2026
    CISA deadline
    3 days
    CVSS severity
    7.8 (high)
  211. Rank 221Red Hat ABRT (Automatic Bug Reporting Tool)

    CVE-2015-5287

    CVE from 2015, added in 2026

    Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  212. Rank 222Linux Kernel

    CVE-2022-0995

    CVE from 2022, added in 2026

    Linux Kernel Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  213. Rank 223Microsoft AD FS

    CVE-2026-56155

    Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  214. Rank 224Cisco Catalyst SD-WAN

    CVE-2026-20245

    Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  215. Rank 225Linux Kernel

    CVE-2022-0492

    CVE from 2022, added in 2026

    Linux Kernel Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 2, 2026
    CISA deadline
    3 days
    CVSS severity
    7.8 (high)
  216. Rank 226Microsoft Defender

    CVE-2026-41091

    Microsoft Defender Link Following Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  217. Rank 227Linux Kernel

    CVE-2026-31431

    Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 1, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  218. Rank 228Microsoft Defender

    CVE-2026-33825

    Ransomware

    Microsoft Defender Insufficient Granularity of Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 22, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  219. Rank 229Microsoft Office

    CVE-2012-1854

    CVE from 2012, added in 2026

    Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  220. Rank 230Adobe Acrobat / Reader

    CVE-2020-9715

    CVE from 2020, added in 2026

    Adobe Acrobat Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  221. Rank 231Microsoft Windows

    CVE-2023-36424

    CVE from 2023, added in 2026

    Microsoft Windows Out-of-Bounds Read Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  222. Rank 232Microsoft Windows

    CVE-2025-60710

    Ransomware

    Microsoft Windows Link Following Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  223. Rank 233TrueConf Client

    CVE-2026-3502

    TrueConf Client Download of Code Without Integrity Check Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 2, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  224. Rank 234Apple iOS / iPadOS / macOS

    CVE-2025-43510

    Apple Multiple Products Improper Locking Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  225. Rank 235Apple Safari / WebKit

    CVE-2021-30952

    CVE from 2021, added in 2026

    Apple Multiple Products Integer Overflow or Wraparound Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  226. Rank 236Apple iOS / iPadOS

    CVE-2023-41974

    CVE from 2023, added in 2026

    Apple iOS and iPadOS Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  227. Rank 237Qualcomm Snapdragon (chipsets and drivers)

    CVE-2026-21385

    Qualcomm Multiple Chipsets Memory Corruption Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 3, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  228. Rank 238Cisco Catalyst SD-WAN

    CVE-2022-20775

    CVE from 2022, added in 2026

    Cisco SD-WAN Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 25, 2026
    CISA deadline
    2 days
    CVSS severity
    7.8 (high)
  229. Rank 239Apple iOS / iPadOS / macOS

    CVE-2026-20700

    Apple Multiple Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  230. Rank 240Microsoft Office

    CVE-2026-21514

    Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  231. Rank 241Microsoft Windows

    CVE-2026-21519

    Microsoft Windows Type Confusion Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  232. Rank 242Microsoft Windows

    CVE-2026-21533

    Microsoft Windows Improper Privilege Management Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  233. Rank 243Linux Kernel

    CVE-2018-14634

    CVE from 2018, added in 2026

    Linux Kernel Integer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  234. Rank 244Microsoft Office

    CVE-2026-21509

    Microsoft Office Security Feature Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  235. Rank 245RARLAB WinRAR

    CVE-2025-6218

    RARLAB WinRAR Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 9, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  236. Rank 246Microsoft Windows

    CVE-2025-62221

    Microsoft Windows Use After Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 9, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  237. Rank 247Google Android

    CVE-2025-48572

    Android Framework Privilege Escalation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 2, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  238. Rank 248VMware (Broadcom) VMware Tools

    CVE-2025-41244

    Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 30, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  239. Rank 249Microsoft Windows

    CVE-2025-24990

    Microsoft Windows Untrusted Pointer Dereference Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  240. Rank 250Microsoft Windows

    CVE-2025-59230

    Microsoft Windows Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  241. Rank 251Linux Kernel

    CVE-2021-22555

    CVE from 2021, added in 2025

    Linux Kernel Heap Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  242. Rank 252Microsoft Windows

    CVE-2021-43226

    RansomwareCVE from 2021, added in 2025

    Microsoft Windows Privilege Escalation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  243. Rank 253Sudo

    CVE-2025-32463

    Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  244. Rank 254Cisco IOS / IOS XE

    CVE-2025-20352

    Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.7 (high)
  245. Rank 255Apache Tomcat

    CVE-2026-34486

    Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 4, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  246. Rank 256KNX Association Protocole KNX

    CVE-2023-4346

    CVE from 2023, added in 2026

    KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 15, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  247. Rank 257SolarWinds Serv-U

    CVE-2026-28318

    SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 5, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  248. Rank 258Oracle WebLogic Server

    CVE-2024-21182

    CVE from 2024, added in 2026

    Oracle WebLogic Server Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 1, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  249. Rank 259Microsoft Defender

    CVE-2026-45498

    Microsoft Defender Denial of Service Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  250. Rank 260PaperCut NG / MF

    CVE-2023-27351

    RansomwareCVE from 2023, added in 2026

    PaperCut NG/MF Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  251. Rank 261Cisco Catalyst SD-WAN

    CVE-2026-20128

    Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  252. Rank 262Cisco Catalyst SD-WAN

    CVE-2026-20133

    Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  253. Rank 263Omnissa (ex-VMware EUC) Workspace ONE UEM (AirWatch)

    CVE-2021-22054

    CVE from 2021, added in 2026

    Omnissa Workspace ONE Server-Side Request Forgery

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  254. Rank 264Ivanti Endpoint Manager (EPM)

    CVE-2026-1603

    Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  255. Rank 265Notepad++

    CVE-2025-15556

    Notepad++ Download of Code Without Integrity Check Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  256. Rank 266GitLab Community / Enterprise Edition (CE/EE)

    CVE-2021-39935

    CVE from 2021, added in 2026

    GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  257. Rank 267Vite

    CVE-2025-31125

    Vite Vitejs Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  258. Rank 268Versa Networks Concerto

    CVE-2025-34026

    Versa Concerto Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  259. Rank 269Prettier eslint-config-prettier

    CVE-2025-54313

    Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  260. Rank 270MongoDB Server

    CVE-2025-14847

    MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  261. Rank 271Gladinet CentreStack / Triofox

    CVE-2025-11371

    Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  262. Rank 272Oracle E-Business Suite

    CVE-2025-61884

    Ransomware

    Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  263. Rank 273Grafana Labs Grafana

    CVE-2021-43798

    CVE from 2021, added in 2025

    Grafana Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 9, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  264. Rank 274N-able N-central

    CVE-2026-18556

    Hunt for compromise (CISA)

    N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 4, 2026
    CISA deadline
    3 days
    CVSS severity
    7.4 (high)
  265. Rank 275JetBrains TeamCity

    CVE-2024-27199

    RansomwareCVE from 2024, added in 2026

    JetBrains TeamCity Relative Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.3 (high)
  266. Rank 276SonicWall SMA 1000

    CVE-2026-15410

    Hunt for compromise (CISA)Ransomware

    SonicWall SMA1000 Appliances Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    7.2 (high)
  267. Rank 277Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-6973

    Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 7, 2026
    CISA deadline
    3 days
    CVSS severity
    7.2 (high)
  268. Rank 278SimpleHelp

    CVE-2024-57728

    RansomwareCVE from 2024, added in 2026

    SimpleHelp Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  269. Rank 279D-Link Routers (DIR, DWR, DSR)

    CVE-2025-29635

    D-Link DIR-823X Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  270. Rank 280Kentico Xperience

    CVE-2025-2749

    Kentico Xperience Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  271. Rank 281TeamT5 ThreatSonar Anti-Ransomware

    CVE-2024-7694

    CVE from 2024, added in 2026

    TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  272. Rank 282Sangoma FreePBX

    CVE-2025-64328

    Sangoma FreePBX OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  273. Rank 283Fortinet FortiWeb

    CVE-2025-58034

    Fortinet FortiWeb OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 18, 2025
    CISA deadline
    7 days
    CVSS severity
    7.2 (high)
  274. Rank 284Adminer

    CVE-2021-21311

    CVE from 2021, added in 2025

    Adminer Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  275. Rank 285Microsoft Windows

    CVE-2026-68820

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 11, 2026
    CISA deadline
    14 days
    CVSS severity
    7.0 (high)
  276. Rank 286Microsoft Windows

    CVE-2025-62215

    Microsoft Windows Race Condition Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 12, 2025
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  277. Rank 287Trend Micro Apex One (ex-OfficeScan)

    CVE-2026-34926

    Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 21, 2026
    CISA deadline
    14 days
    CVSS severity
    6.7 (medium)
  278. Rank 288SonicWall SMA 1000

    CVE-2025-40602

    SonicWall SMA1000 Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    7 days
    CVSS severity
    6.6 (medium)
  279. Rank 289Cisco Catalyst SD-WAN

    CVE-2026-20262

    Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 15, 2026
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  280. Rank 290Microsoft SharePoint Server

    CVE-2026-32201

    Microsoft SharePoint Server Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 14, 2026
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  281. Rank 291Microsoft Windows

    CVE-2026-21525

    Microsoft Windows NULL Pointer Dereference Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    6.2 (medium)
  282. Rank 292Microsoft Exchange Server

    CVE-2026-42897

    Microsoft Exchange Server Cross-Site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 15, 2026
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  283. Rank 293Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-48700

    Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    6.1 (medium)
  284. Rank 294Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-66376

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 18, 2026
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  285. Rank 295Roundcube Webmail

    CVE-2025-68461

    RoundCube Webmail Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 20, 2026
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  286. Rank 296Libraesva Email Security Gateway

    CVE-2025-59689

    Libraesva Email Security Gateway Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  287. Rank 297Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-68686

    Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 27, 2026
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  288. Rank 298WordPress Core

    CVE-2026-60137

    WordPress Core SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 21, 2026
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  289. Rank 299Arista EOS

    CVE-2026-7473

    Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 9, 2026
    CISA deadline
    14 days
    CVSS severity
    5.8 (medium)
  290. Rank 300Apple iOS / iPadOS / macOS

    CVE-2025-43520

    Apple Multiple Products Classic Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 20, 2026
    CISA deadline
    14 days
    CVSS severity
    5.5 (medium)
  291. Rank 301Microsoft Windows

    CVE-2026-20805

    Microsoft Windows Information Disclosure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 13, 2026
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  292. Rank 302Google Android

    CVE-2025-48633

    Android Framework Information Disclosure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 2, 2025
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  293. Rank 303Cisco Catalyst SD-WAN

    CVE-2026-20122

    Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    5.4 (medium)
  294. Rank 304OpenPLC ScadaBR

    CVE-2021-26829

    CVE from 2021, added in 2025

    OpenPLC ScadaBR Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 28, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  295. Rank 305Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-27915

    Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 7, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  296. Rank 306JFrog Artifactory

    CVE-2026-66384

    JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 27, 2026
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  297. Rank 307Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20316

    Ransomware

    Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 29, 2026
    CISA deadline
    3 days
    CVSS severity
    5.3 (medium)
  298. Rank 308Red Hat libuser

    CVE-2015-3246

    CVE from 2015, added in 2026

    Red Hat Libuser Race Condition Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    14 days
    CVSS severity
    5.1 (medium)
  299. Rank 309IGEL OS

    CVE-2025-47827

    IGEL OS Use of a Key Past its Expiration Date Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 14, 2025
    CISA deadline
    21 days
    CVSS severity
    4.6 (medium)
  300. Rank 310Microsoft Windows

    CVE-2026-32202

    Microsoft Windows Protection Mechanism Failure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 28, 2026
    CISA deadline
    14 days
    CVSS severity
    4.3 (medium)
  301. Rank 311Wing FTP Server

    CVE-2025-47813

    Wing FTP Server Information Disclosure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 16, 2026
    CISA deadline
    14 days
    CVSS severity
    4.3 (medium)
  302. Rank 312Apple iOS / iPadOS / macOS

    CVE-2025-43300

    Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  303. Rank 313Cisco Identity Services Engine (ISE)

    CVE-2025-20281

    Cisco Identity Services Engine Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 28, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  304. Rank 314Cisco Identity Services Engine (ISE)

    CVE-2025-20337

    Cisco Identity Services Engine Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 28, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  305. Rank 315Wing FTP Server

    CVE-2025-47812

    Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 14, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  306. Rank 316Erlang/OTP

    CVE-2025-32433

    Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  307. Rank 317Commvault Command Center

    CVE-2025-34028

    Commvault Command Center Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 2, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  308. Rank 318Apple Safari / WebKit

    CVE-2025-24201

    Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 13, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  309. Rank 319Apple iOS / iPadOS / macOS

    CVE-2025-24085

    Apple Multiple Products Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 29, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  310. Rank 320OSGeo GeoServer

    CVE-2022-24816

    CVE from 2022, added in 2024

    OSGeo GeoServer JAI-EXT Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 26, 2024
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  311. Rank 321CrushFTP

    CVE-2024-4040

    CrushFTP VFS Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  312. Rank 322Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-3400

    Ransomware

    Palo Alto Networks PAN-OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 12, 2024
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  313. Rank 323ConnectWise ScreenConnect

    CVE-2024-1709

    Ransomware

    ConnectWise ScreenConnect Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 22, 2024
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  314. Rank 324Cisco IOS / IOS XE

    CVE-2023-20198

    Cisco IOS XE Web UI Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 16, 2023
    CISA deadline
    4 days
    CVSS severity
    10.0 (critical)
  315. Rank 325SAP NetWeaver

    CVE-2022-22536

    SAP Multiple Products HTTP Request Smuggling Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  316. Rank 326Mozilla Firefox

    CVE-2019-11708

    CVE from 2019, added in 2022

    Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  317. Rank 327Spring Cloud Gateway

    CVE-2022-22947

    VMware Spring Cloud Gateway Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 16, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  318. Rank 328Redis Server

    CVE-2022-0543

    Debian-specific Redis Server Lua Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  319. Rank 329Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2020-2021

    RansomwareCVE from 2020, added in 2022

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  320. Rank 330Microsoft Windows

    CVE-2020-0796

    RansomwareCVE from 2020, added in 2022

    Microsoft SMBv3 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  321. Rank 331Elastic Kibana

    CVE-2019-7609

    CVE from 2019, added in 2022

    Kibana Arbitrary Code Execution

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  322. Rank 332Apache Log4j

    CVE-2021-44228

    Ransomware

    Apache Log4j2 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  323. Rank 333SAP NetWeaver

    CVE-2010-5326

    CVE from 2010, added in 2021

    SAP NetWeaver Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  324. Rank 334Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2019-11510

    RansomwareCVE from 2019, added in 2021

    Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  325. Rank 335Microsoft Windows

    CVE-2020-1350

    Microsoft Windows DNS Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  326. Rank 336Microsoft Active Directory

    CVE-2020-1472

    Ransomware

    Microsoft Netlogon Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  327. Rank 337Oracle Solaris

    CVE-2020-14871

    Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  328. Rank 338SAP NetWeaver

    CVE-2020-6287

    SAP NetWeaver Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  329. Rank 339GitLab Community / Enterprise Edition (CE/EE)

    CVE-2021-22205

    Ransomware

    GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  330. Rank 340Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22893

    Ransomware

    Ivanti Pulse Connect Secure Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  331. Rank 341SolarWinds Serv-U

    CVE-2021-35211

    Ransomware

    SolarWinds Serv-U Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  332. Rank 342Cisco ASA / Firepower (FTD)

    CVE-2025-20333

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2025
    CISA deadline
    1 day
    CVSS severity
    9.9 (critical)
  333. Rank 343Wazuh Server

    CVE-2025-24016

    Wazuh Server Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 10, 2025
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  334. Rank 344Qlik Sense

    CVE-2023-48365

    RansomwareCVE from 2023, added in 2025

    Qlik Sense HTTP Tunneling Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 13, 2025
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  335. Rank 345Qlik Sense

    CVE-2023-41265

    Ransomware

    Qlik Sense HTTP Tunneling Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  336. Rank 346Jenkins Plugins

    CVE-2019-1003029

    CVE from 2019, added in 2022

    Jenkins Script Security Plugin Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  337. Rank 347Jenkins Plugins

    CVE-2019-1003030

    CVE from 2019, added in 2022

    Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  338. Rank 348MongoDB mongo-express

    CVE-2019-10758

    CVE from 2019, added in 2021

    MongoDB mongo-express Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.9 (critical)
  339. Rank 349Google Chrome / Chromium

    CVE-2025-10585

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 23, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  340. Rank 350Sangoma FreePBX

    CVE-2025-57819

    Sangoma FreePBX Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 29, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  341. Rank 351Citrix NetScaler ADC / Gateway

    CVE-2025-7775

    Citrix NetScaler Memory Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 26, 2025
    CISA deadline
    2 days
    CVSS severity
    9.8 (critical)
  342. Rank 352Trend Micro Apex One (ex-OfficeScan)

    CVE-2025-54948

    Trend Micro Apex One OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  343. Rank 353SysAid On-Prem

    CVE-2025-2776

    SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  344. Rank 354CrushFTP

    CVE-2025-54309

    CrushFTP Unprotected Alternate Channel Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  345. Rank 355Microsoft SharePoint Server

    CVE-2025-53770

    Ransomware

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2025
    CISA deadline
    1 day
    CVSS severity
    9.8 (critical)
  346. Rank 356Fortinet FortiWeb

    CVE-2025-25257

    Fortinet FortiWeb SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  347. Rank 357MRLG (Multi-Router Looking Glass) Multi-Router Looking Glass (MRLG)

    CVE-2014-3931

    CVE from 2014, added in 2025

    Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  348. Rank 358PHPMailer

    CVE-2016-10033

    CVE from 2016, added in 2025

    PHPMailer Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  349. Rank 359Citrix NetScaler ADC / Gateway

    CVE-2025-6543

    Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 30, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  350. Rank 360D-Link Routers (DIR, DWR, DSR)

    CVE-2024-0769

    D-Link DIR-859 Router Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  351. Rank 361AMI MegaRAC SPx

    CVE-2024-54085

    AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  352. Rank 362ASUS Routers (RT, GT, ZenWiFi)

    CVE-2021-32030

    CVE from 2021, added in 2025

    ASUS Routers Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  353. Rank 363Craft CMS

    CVE-2024-56145

    Craft CMS Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  354. Rank 364Samsung MagicINFO Server

    CVE-2025-4632

    Samsung MagicINFO 9 Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  355. Rank 365DrayTek Vigor (routers)

    CVE-2024-12987

    DrayTek Vigor Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 15, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  356. Rank 366Fortinet FortiVoice / FortiFone

    CVE-2025-32756

    Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  357. Rank 367GeoVision Cameras and video servers

    CVE-2024-11120

    GeoVision Devices OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  358. Rank 368GeoVision Cameras and video servers

    CVE-2024-6047

    GeoVision Devices OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  359. Rank 369Langflow

    CVE-2025-3248

    Ransomware

    Langflow Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 5, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  360. Rank 370Yii Framework Yii

    CVE-2024-58136

    Yiiframework Yii Improper Protection of Alternate Path Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  361. Rank 371SAP NetWeaver

    CVE-2025-31324

    Ransomware

    SAP NetWeaver Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 29, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  362. Rank 372Qualitia Active! Mail

    CVE-2025-42599

    Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 28, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  363. Rank 373Apple iOS / iPadOS / macOS

    CVE-2025-31200

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  364. Rank 374Apple iOS / iPadOS / macOS

    CVE-2025-31201

    Apple Multiple Products Arbitrary Read and Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  365. Rank 375Gladinet CentreStack / Triofox

    CVE-2025-30406

    Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 8, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  366. Rank 376CrushFTP

    CVE-2025-31161

    Ransomware

    CrushFTP Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  367. Rank 377Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2025-22457

    Ransomware

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  368. Rank 378Apache Tomcat

    CVE-2025-24813

    Apache Tomcat Path Equivalence Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 1, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  369. Rank 379Cisco Smart Licensing Utility

    CVE-2024-20439

    Cisco Smart Licensing Utility Static Credential Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  370. Rank 380Sitecore Experience Platform / Manager (XP / XM)

    CVE-2019-9874

    CVE from 2019, added in 2025

    Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 26, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  371. Rank 381Edimax IC-7100 IP Camera

    CVE-2025-1316

    Edimax IC-7100 IP Camera OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 19, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  372. Rank 382Hitachi Vantara Pentaho Business Analytics (BA) Server

    CVE-2022-43939

    CVE from 2022, added in 2025

    Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  373. Rank 383Progress WhatsUp Gold

    CVE-2024-4885

    Progress WhatsUp Gold Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  374. Rank 384Microsoft Partner Center

    CVE-2024-49035

    Microsoft Partner Center Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  375. Rank 385Adobe ColdFusion

    CVE-2017-3066

    CVE from 2017, added in 2025

    Adobe ColdFusion Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  376. Rank 386Microsoft Power Pages

    CVE-2025-24989

    Microsoft Power Pages Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  377. Rank 387SonicWall SonicOS

    CVE-2024-53704

    Ransomware

    SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  378. Rank 388Sophos Firewall (SFOS, ex-XG)

    CVE-2020-15069

    CVE from 2020, added in 2025

    Sophos XG Firewall Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  379. Rank 389Microsoft Outlook

    CVE-2024-21413

    Microsoft Outlook Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  380. Rank 390Paessler PRTG Network Monitor

    CVE-2018-19410

    CVE from 2018, added in 2025

    Paessler PRTG Network Monitor Local File Inclusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  381. Rank 391SonicWall SMA 1000

    CVE-2025-23006

    Ransomware

    SonicWall SMA1000 Appliances Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  382. Rank 392Aviatrix Controller

    CVE-2024-50603

    Aviatrix Controllers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 16, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  383. Rank 393Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-55591

    Ransomware

    Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  384. Rank 394Oracle WebLogic Server

    CVE-2020-2883

    CVE from 2020, added in 2025

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  385. Rank 395BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2024-12356

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 19, 2024
    CISA deadline
    8 days
    CVSS severity
    9.8 (critical)
  386. Rank 396Cleo Harmony / VLTrader / LexiCom

    CVE-2024-55956

    Ransomware

    Cleo Multiple Products Unauthenticated File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  387. Rank 397Cleo Harmony / VLTrader / LexiCom

    CVE-2024-50623

    Ransomware

    Cleo Multiple Products Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  388. Rank 398CyberPanel (CyberPersons) CyberPanel

    CVE-2024-51378

    Ransomware

    CyberPanel Incorrect Default Permissions Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 4, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  389. Rank 399Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2024-11667

    Ransomware

    Zyxel Multiple Firewalls Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 3, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  390. Rank 400ProjectSend

    CVE-2024-11680

    ProjectSend Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 3, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  391. Rank 401Array Networks ArrayOS AG / vxAG

    CVE-2023-28461

    Ransomware

    Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  392. Rank 402VMware (Broadcom) vCenter Server

    CVE-2024-38812

    VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  393. Rank 403VMware (Broadcom) vCenter Server

    CVE-2024-38813

    VMware vCenter Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  394. Rank 404Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-0012

    Ransomware

    Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  395. Rank 405Progress Kemp LoadMaster

    CVE-2024-1212

    Progress Kemp LoadMaster OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  396. Rank 406Nostromo nhttpd

    CVE-2019-16278

    CVE from 2019, added in 2024

    Nostromo nhttpd Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  397. Rank 407CyberPanel (CyberPersons) CyberPanel

    CVE-2024-51567

    Ransomware

    CyberPanel Incorrect Default Permissions Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  398. Rank 408Palo Alto Networks Expedition

    CVE-2024-5910

    Palo Alto Networks Expedition Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  399. Rank 409Fortinet FortiManager / FortiAnalyzer

    CVE-2024-47575

    Fortinet FortiManager Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 23, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  400. Rank 410ScienceLogic SL1

    CVE-2024-9537

    ScienceLogic SL1 Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 21, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  401. Rank 411Veeam Backup & Replication

    CVE-2024-40711

    Ransomware

    Veeam Backup and Replication Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  402. Rank 412Mozilla Firefox

    CVE-2024-9680

    Ransomware

    Mozilla Firefox Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  403. Rank 413Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-23113

    Fortinet Multiple Products Format String Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  404. Rank 414Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2024-45519

    Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 3, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  405. Rank 415SAP Commerce Cloud (Hybris)

    CVE-2019-0344

    CVE from 2019, added in 2024

    SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  406. Rank 416DrayTek Vigor (routers)

    CVE-2020-15415

    CVE from 2020, added in 2024

    DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  407. Rank 417Ivanti Virtual Traffic Manager (vTM)

    CVE-2024-7593

    Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 24, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  408. Rank 418Oracle WebLogic Server

    CVE-2020-14644

    CVE from 2020, added in 2024

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  409. Rank 419Oracle ADF Faces

    CVE-2022-21445

    CVE from 2022, added in 2024

    Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  410. Rank 420Apache HugeGraph

    CVE-2024-27348

    Apache HugeGraph-Server Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  411. Rank 421Progress WhatsUp Gold

    CVE-2024-6670

    Ransomware

    Progress WhatsUp Gold SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 16, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  412. Rank 422SonicWall SonicOS

    CVE-2024-40766

    Ransomware

    SonicWall SonicOS Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  413. Rank 423Apache OFBiz

    CVE-2024-38856

    Apache OFBiz Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 27, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  414. Rank 424Dahua IP Camera Firmware

    CVE-2021-33044

    CVE from 2021, added in 2024

    Dahua IP Camera Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  415. Rank 425Dahua IP Camera Firmware

    CVE-2021-33045

    CVE from 2021, added in 2024

    Dahua IP Camera Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  416. Rank 426Jenkins Core

    CVE-2024-23897

    Ransomware

    Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 19, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  417. Rank 427SolarWinds Web Help Desk

    CVE-2024-28986

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  418. Rank 428Apache OFBiz

    CVE-2024-32113

    Apache OFBiz Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  419. Rank 429Acronis Cyber Infrastructure (ACI)

    CVE-2023-45249

    Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  420. Rank 430ServiceNow Now Platform

    CVE-2024-4879

    ServiceNow Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  421. Rank 431ServiceNow Now Platform

    CVE-2024-5217

    ServiceNow Incomplete List of Disallowed Inputs Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  422. Rank 432Adobe Commerce (Magento)

    CVE-2024-34102

    Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  423. Rank 433OSGeo GeoServer

    CVE-2024-36401

    OSGeo GeoServer GeoTools Eval Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  424. Rank 434Rejetto HTTP File Server (HFS)

    CVE-2024-23692

    Ransomware

    Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  425. Rank 435Progress Telerik Report Server

    CVE-2024-4358

    Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  426. Rank 436PHP

    CVE-2024-4577

    Ransomware

    PHP-CGI OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 12, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  427. Rank 437NextGen Healthcare Mirth Connect

    CVE-2023-43208

    Ransomware

    NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  428. Rank 438GitLab Community / Enterprise Edition (CE/EE)

    CVE-2023-7028

    GitLab Community and Enterprise Editions Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  429. Rank 439Nice (Linear) Linear eMerge E3-Series

    CVE-2019-7256

    CVE from 2019, added in 2024

    Nice Linear eMerge E3-Series OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  430. Rank 440Ivanti Cloud Services Appliance (CSA)

    CVE-2021-44529

    RansomwareCVE from 2021, added in 2024

    Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  431. Rank 441Fortinet FortiClient EMS

    CVE-2023-48788

    Ransomware

    Fortinet FortiClient EMS SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  432. Rank 442JetBrains TeamCity

    CVE-2024-27198

    Ransomware

    JetBrains TeamCity Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  433. Rank 443Sunhillo SureLine

    CVE-2021-36380

    CVE from 2021, added in 2024

    Sunhillo SureLine OS Command Injection Vulnerablity

    Added more than a year ago: ranked by severity.

    Added
    Mar 5, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  434. Rank 444Microsoft Exchange Server

    CVE-2024-21410

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  435. Rank 445Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-21762

    Ransomware

    Fortinet FortiOS Out-of-Bound Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 9, 2024
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  436. Rank 446Atlassian Confluence Server / Data Center

    CVE-2023-22527

    Ransomware

    Atlassian Confluence Data Center and Server Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 24, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  437. Rank 447VMware (Broadcom) vCenter Server

    CVE-2023-34048

    VMware vCenter Server Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 22, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  438. Rank 448Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35082

    Ransomware

    Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  439. Rank 449Microsoft SharePoint Server

    CVE-2023-29357

    Ransomware

    Microsoft SharePoint Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  440. Rank 450D-Link DSL modem-routers

    CVE-2016-20017

    CVE from 2016, added in 2024

    D-Link DSL-2750B Devices Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  441. Rank 451Apache Superset

    CVE-2023-27524

    Apache Superset Insecure Default Initialization of Resource Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  442. Rank 452Adobe ColdFusion

    CVE-2023-29300

    Ransomware

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  443. Rank 453Adobe ColdFusion

    CVE-2023-38203

    Ransomware

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  444. Rank 454Unitronics Vision PLC and HMI

    CVE-2023-6448

    Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 11, 2023
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  445. Rank 455Oracle WebLogic Server

    CVE-2020-2551

    CVE from 2020, added in 2023

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  446. Rank 456Sophos Web Appliance

    CVE-2023-1671

    Sophos Web Appliance Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  447. Rank 457Juniper Junos OS

    CVE-2023-36845

    Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    9.8 (critical)
  448. Rank 458SysAid On-Prem

    CVE-2023-47246

    Ransomware

    SysAid Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  449. Rank 459Atlassian Confluence Server / Data Center

    CVE-2023-22518

    Ransomware

    Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  450. Rank 460Apache ActiveMQ

    CVE-2023-46604

    Ransomware

    Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  451. Rank 461F5 BIG-IP

    CVE-2023-46747

    Ransomware

    F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 31, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  452. Rank 462Atlassian Confluence Server / Data Center

    CVE-2023-22515

    Ransomware

    Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 5, 2023
    CISA deadline
    8 days
    CVSS severity
    9.8 (critical)
  453. Rank 463JetBrains TeamCity

    CVE-2023-42793

    Ransomware

    JetBrains TeamCity Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 4, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  454. Rank 464Red Hat JBoss RichFaces

    CVE-2018-14667

    CVE from 2018, added in 2023

    Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 28, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  455. Rank 465Realtek Router SDKs (Jungle, AP-Router)

    CVE-2014-8361

    CVE from 2014, added in 2023

    Realtek SDK Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  456. Rank 466Laravel Ignition

    CVE-2021-3129

    RansomwareCVE from 2021, added in 2023

    Laravel Ignition File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  457. Rank 467Apache RocketMQ

    CVE-2023-33246

    Apache RocketMQ Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 6, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  458. Rank 468Ivanti Sentry

    CVE-2023-38035

    Ransomware

    Ivanti Sentry Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  459. Rank 469Adobe ColdFusion

    CVE-2023-26359

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  460. Rank 470Citrix ShareFile

    CVE-2023-24489

    Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  461. Rank 471Zyxel Home gateways and routers (DSL, CPE)

    CVE-2017-18368

    CVE from 2017, added in 2023

    Zyxel P660HN-T1A Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  462. Rank 472Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35078

    Ransomware

    Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 25, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  463. Rank 473Citrix NetScaler ADC / Gateway

    CVE-2023-3519

    Ransomware

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 19, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  464. Rank 474CONTEC (SolarView) SolarView Compact

    CVE-2022-29303

    SolarView Compact Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  465. Rank 475Netwrix Auditor

    CVE-2022-31199

    Ransomware

    Netwrix Auditor Insecure Object Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  466. Rank 476D-Link Routers (DIR, DWR, DSR)

    CVE-2019-17621

    CVE from 2019, added in 2023

    D-Link DIR-859 Router Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  467. Rank 477Zyxel NAS

    CVE-2023-27992

    Zyxel Multiple NAS Devices Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  468. Rank 478Roundcube Webmail

    CVE-2020-12641

    CVE from 2020, added in 2023

    Roundcube Webmail Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  469. Rank 479Roundcube Webmail

    CVE-2021-44026

    CVE from 2021, added in 2023

    Roundcube Webmail SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  470. Rank 480VMware (Broadcom) Aria Operations for Networks (ex-vRealize Network Insight)

    CVE-2023-20887

    Vmware Aria Operations for Networks Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  471. Rank 481Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2023-27997

    Ransomware

    Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  472. Rank 482Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2023-33009

    Zyxel Multiple Firewalls Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 5, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  473. Rank 483Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2023-33010

    Zyxel Multiple Firewalls Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 5, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  474. Rank 484Progress MOVEit Transfer

    CVE-2023-34362

    Ransomware

    Progress MOVEit Transfer SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  475. Rank 485Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2023-28771

    Zyxel Multiple Firewalls OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 31, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  476. Rank 486Barracuda Networks Email Security Gateway (ESG)

    CVE-2023-2868

    Barracuda Networks ESG Appliance Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 26, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  477. Rank 487Oracle Java SE (JRE / JDK)

    CVE-2016-3427

    CVE from 2016, added in 2023

    Oracle Java SE and JRockit Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  478. Rank 488Apache Tomcat

    CVE-2016-8735

    CVE from 2016, added in 2023

    Apache Tomcat Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  479. Rank 489Ruckus Wireless Wi-Fi access points and controllers

    CVE-2023-25717

    Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  480. Rank 490PaperCut NG / MF

    CVE-2023-27350

    Ransomware

    PaperCut MF/NG Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  481. Rank 491Novi Survey

    CVE-2023-29492

    Novi Survey Insecure Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  482. Rank 492Veritas Backup Exec

    CVE-2021-27877

    RansomwareCVE from 2021, added in 2023

    Veritas Backup Exec Agent Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  483. Rank 493Samba

    CVE-2017-7494

    RansomwareCVE from 2017, added in 2023

    Samba Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  484. Rank 494Fortra Cobalt Strike

    CVE-2022-42948

    Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  485. Rank 495Adobe ColdFusion

    CVE-2023-26360

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  486. Rank 496Microsoft Office

    CVE-2023-23397

    Microsoft Office Outlook Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 14, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  487. Rank 497Teclib GLPI

    CVE-2022-35914

    Teclib GLPI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  488. Rank 498IBM Aspera Faspex

    CVE-2022-47986

    Ransomware

    IBM Aspera Faspex Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  489. Rank 499Cacti

    CVE-2022-46169

    Cacti Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  490. Rank 500Oracle E-Business Suite

    CVE-2022-21587

    Ransomware

    Oracle E-Business Suite Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  491. Rank 501Progress Telerik UI for ASP.NET AJAX

    CVE-2017-11357

    RansomwareCVE from 2017, added in 2023

    Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 26, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  492. Rank 502ManageEngine (Zoho) Multiple products

    CVE-2022-47966

    Ransomware

    Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 23, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  493. Rank 503CWP (Control Web Panel / CentOS Web Panel) Control Web Panel

    CVE-2022-44877

    CWP Control Web Panel OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  494. Rank 504Microsoft Exchange Server

    CVE-2022-41080

    Ransomware

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  495. Rank 505Veeam Backup & Replication

    CVE-2022-26501

    Ransomware

    Veeam Backup & Replication Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  496. Rank 506Citrix NetScaler ADC / Gateway

    CVE-2022-27518

    Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  497. Rank 507Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-42475

    Ransomware

    Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  498. Rank 508Oracle Identity and Access Management (OIM / OAM)

    CVE-2021-35587

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  499. Rank 509GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19323

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  500. Rank 510Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-41352

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 20, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  501. Rank 511Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-40684

    Ransomware

    Fortinet Multiple Products Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  502. Rank 512Sophos Firewall (SFOS, ex-XG)

    CVE-2022-3236

    Sophos Firewall Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 23, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  503. Rank 513ManageEngine (Zoho) PAM360 / Password Manager Pro

    CVE-2022-35405

    Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 22, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  504. Rank 514Oracle WebLogic Server

    CVE-2018-2628

    CVE from 2018, added in 2022

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  505. Rank 515D-Link Routers (DIR, DWR, DSR)

    CVE-2018-6530

    RansomwareCVE from 2018, added in 2022

    D-Link Multiple Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  506. Rank 516MikroTik RouterOS

    CVE-2018-7445

    CVE from 2018, added in 2022

    MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  507. Rank 517Spring Cloud Function

    CVE-2022-22963

    VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  508. Rank 518Apache APISIX

    CVE-2022-24112

    Apache APISIX Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  509. Rank 519Apache CouchDB

    CVE-2022-24706

    Apache CouchDB Insecure Default Initialization of Resource Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  510. Rank 520dotCMS

    CVE-2022-26352

    Ransomware

    dotCMS Unrestricted Upload of File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  511. Rank 521Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2017-15944

    CVE from 2017, added in 2022

    Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  512. Rank 522Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-37042

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  513. Rank 523Atlassian Confluence Server / Data Center

    CVE-2022-26138

    Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  514. Rank 524Mitel MiVoice Connect

    CVE-2022-29499

    Ransomware

    Mitel MiVoice Connect Data Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  515. Rank 525SAP NetWeaver

    CVE-2016-2386

    CVE from 2016, added in 2022

    SAP NetWeaver SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  516. Rank 526Adobe Acrobat / Reader

    CVE-2011-2462

    CVE from 2011, added in 2022

    Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  517. Rank 527NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-6862

    CVE from 2017, added in 2022

    NETGEAR Multiple Devices Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  518. Rank 528QNAP Photo Station

    CVE-2019-7192

    RansomwareCVE from 2019, added in 2022

    QNAP Photo Station Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  519. Rank 529QNAP NAS (QTS / QuTS hero)

    CVE-2019-7193

    RansomwareCVE from 2019, added in 2022

    QNAP QTS Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  520. Rank 530QNAP Photo Station

    CVE-2019-7194

    RansomwareCVE from 2019, added in 2022

    QNAP Photo Station Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  521. Rank 531QNAP Photo Station

    CVE-2019-7195

    RansomwareCVE from 2019, added in 2022

    QNAP Photo Station Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  522. Rank 532Atlassian Confluence Server / Data Center

    CVE-2022-26134

    Ransomware

    Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2022
    CISA deadline
    4 days
    CVSS severity
    9.8 (critical)
  523. Rank 533Oracle Java SE (JRE / JDK)

    CVE-2010-0840

    CVE from 2010, added in 2022

    Oracle JRE Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  524. Rank 534Oracle Fusion Middleware

    CVE-2012-1710

    RansomwareCVE from 2012, added in 2022

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  525. Rank 535Oracle Java SE (JRE / JDK)

    CVE-2013-0422

    RansomwareCVE from 2013, added in 2022

    Oracle JRE Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  526. Rank 536Adobe Acrobat / Reader

    CVE-2014-0546

    CVE from 2014, added in 2022

    Adobe Reader and Acrobat Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  527. Rank 537Microsoft Windows

    CVE-2017-8543

    CVE from 2017, added in 2022

    Microsoft Windows Search Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  528. Rank 538QNAP NAS (QTS / QuTS hero)

    CVE-2018-19949

    RansomwareCVE from 2018, added in 2022

    QNAP NAS File Station Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  529. Rank 539Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2022-30525

    Zyxel Multiple Firewalls OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 16, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  530. Rank 540F5 BIG-IP

    CVE-2022-1388

    Ransomware

    F5 BIG-IP Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 10, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  531. Rank 541WSO2 API Manager, Identity Server, Integrator

    CVE-2022-29464

    Ransomware

    WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  532. Rank 542Meta WhatsApp

    CVE-2019-3568

    CVE from 2019, added in 2022

    WhatsApp VOIP Stack Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  533. Rank 543Alcatel-Lucent Enterprise OmniPCX Enterprise

    CVE-2007-3010

    CVE from 2007, added in 2022

    Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  534. Rank 544Ubiquiti airOS (airMAX)

    CVE-2010-5330

    CVE from 2010, added in 2022

    Ubiquiti AirOS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  535. Rank 545InduSoft Web Studio

    CVE-2014-0780

    CVE from 2014, added in 2022

    InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  536. Rank 546Crestron AirMedia (AM-100, AM-101)

    CVE-2019-3929

    CVE from 2019, added in 2022

    Crestron Multiple Products Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  537. Rank 547VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2022-22954

    Ransomware

    VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 14, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  538. Rank 548Kaseya VSA

    CVE-2018-20753

    RansomwareCVE from 2018, added in 2022

    Kaseya VSA Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  539. Rank 549Drupal Core

    CVE-2018-7602

    RansomwareCVE from 2018, added in 2022

    Drupal Core Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  540. Rank 550Progress Telerik UI for ASP.NET AJAX

    CVE-2017-11317

    CVE from 2017, added in 2022

    Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  541. Rank 551QNAP NAS (QTS / QuTS hero)

    CVE-2020-2509

    CVE from 2020, added in 2022

    QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  542. Rank 552Microsoft Windows

    CVE-2021-31166

    Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 6, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  543. Rank 553Spring Framework

    CVE-2022-22965

    Spring Framework JDK 9+ Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  544. Rank 554QNAP NAS (QTS / QuTS hero)

    CVE-2021-28799

    Ransomware

    QNAP NAS Improper Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  545. Rank 555Sophos Firewall (SFOS, ex-XG)

    CVE-2022-1040

    Sophos Firewall Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  546. Rank 556Trend Micro Apex Central

    CVE-2022-26871

    Trend Micro Apex Central Arbitrary File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  547. Rank 557Oracle Java SE (JRE / JDK)

    CVE-2012-5076

    CVE from 2012, added in 2022

    Oracle Java SE Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  548. Rank 558Oracle Java SE (JRE / JDK)

    CVE-2013-2465

    RansomwareCVE from 2013, added in 2022

    Oracle Java SE Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  549. Rank 559Adobe Acrobat / Reader

    CVE-2013-2729

    CVE from 2013, added in 2022

    Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  550. Rank 560HPE Network Node Manager (OpenView NNM)

    CVE-2005-2773

    CVE from 2005, added in 2022

    HP OpenView Network Node Manager Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  551. Rank 561phpMyAdmin

    CVE-2009-1151

    CVE from 2009, added in 2022

    phpMyAdmin Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  552. Rank 562Adobe ColdFusion

    CVE-2010-2861

    RansomwareCVE from 2010, added in 2022

    Adobe ColdFusion Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  553. Rank 563Exim

    CVE-2010-4344

    CVE from 2010, added in 2022

    Exim Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  554. Rank 564PHP

    CVE-2012-1823

    CVE from 2012, added in 2022

    PHP-CGI Query String Parameter Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  555. Rank 565Apache Struts

    CVE-2013-2251

    CVE from 2013, added in 2022

    Apache Struts Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  556. Rank 566HPE ProCurve Manager (PCM, PCM+, IDM)

    CVE-2013-4810

    CVE from 2013, added in 2022

    HP Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  557. Rank 567Rejetto HTTP File Server (HFS)

    CVE-2014-6287

    CVE from 2014, added in 2022

    Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  558. Rank 568Elastic Elasticsearch

    CVE-2015-1427

    CVE from 2015, added in 2022

    Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  559. Rank 569NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2016-10174

    CVE from 2016, added in 2022

    NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  560. Rank 570NETGEAR Wi-Fi access points (WAC, WNAP)

    CVE-2016-1555

    CVE from 2016, added in 2022

    NETGEAR Multiple WAP Devices Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  561. Rank 571Cisco IOS / IOS XE

    CVE-2017-3881

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  562. Rank 572Citrix SD-WAN

    CVE-2017-6316

    CVE from 2017, added in 2022

    Citrix Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  563. Rank 573Cisco RV routers (Small Business)

    CVE-2018-0125

    CVE from 2018, added in 2022

    Cisco VPN Routers Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  564. Rank 574Cisco Secure Access Control System (ACS)

    CVE-2018-0147

    CVE from 2018, added in 2022

    Cisco Secure Access Control System Java Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  565. Rank 575Quest KACE Systems Management Appliance (SMA)

    CVE-2018-11138

    RansomwareCVE from 2018, added in 2022

    Quest KACE System Management Appliance Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  566. Rank 576Spring Data

    CVE-2018-1273

    RansomwareCVE from 2018, added in 2022

    VMware Tanzu Spring Data Commons Property Binder Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  567. Rank 577LG N1A1 NAS

    CVE-2018-14839

    CVE from 2018, added in 2022

    LG N1A1 NAS Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  568. Rank 578Kentico Xperience

    CVE-2019-10068

    CVE from 2019, added in 2022

    Kentico Xperience Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  569. Rank 579PHP

    CVE-2019-11043

    RansomwareCVE from 2019, added in 2022

    PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  570. Rank 580Citrix SD-WAN

    CVE-2019-12989

    CVE from 2019, added in 2022

    Citrix SD-WAN and NetScaler SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  571. Rank 581Webmin

    CVE-2019-15107

    RansomwareCVE from 2019, added in 2022

    Webmin Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  572. Rank 582Juniper Junos OS

    CVE-2020-1631

    CVE from 2020, added in 2022

    Juniper Junos OS Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  573. Rank 583QNAP Helpdesk

    CVE-2020-2506

    CVE from 2020, added in 2022

    QNAP Helpdesk Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  574. Rank 584Sophos SG UTM

    CVE-2020-25223

    CVE from 2020, added in 2022

    Sophos SG UTM Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  575. Rank 585OpenBSD OpenSMTPD

    CVE-2020-7247

    CVE from 2020, added in 2022

    OpenSMTPD Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  576. Rank 586Zyxel NAS

    CVE-2020-9054

    CVE from 2020, added in 2022

    Zyxel Multiple NAS Devices OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  577. Rank 587Citrix ShareFile

    CVE-2021-22941

    Ransomware

    Citrix ShareFile Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  578. Rank 588Sitecore Experience Platform / Manager (XP / XM)

    CVE-2021-42237

    Ransomware

    Sitecore XP Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  579. Rank 589Mitel MiCollab

    CVE-2022-26143

    MiCollab, MiVoice Business Express Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  580. Rank 590WatchGuard Firebox / XTM (Fireware)

    CVE-2022-26318

    WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  581. Rank 591SonicWall SonicOS

    CVE-2020-5135

    RansomwareCVE from 2020, added in 2022

    SonicWall SonicOS Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  582. Rank 592Adobe ColdFusion

    CVE-2013-0625

    CVE from 2013, added in 2022

    Adobe ColdFusion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    9.8 (critical)
  583. Rank 593NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-6077

    CVE from 2017, added in 2022

    NETGEAR DGN2200 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    9.8 (critical)
  584. Rank 594Atlassian Jira Server / Data Center

    CVE-2019-11581

    CVE from 2019, added in 2022

    Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    9.8 (critical)
  585. Rank 595Microsoft Forefront TMG

    CVE-2011-1889

    CVE from 2011, added in 2022

    Microsoft Forefront TMG Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  586. Rank 596Oracle Java SE (JRE / JDK)

    CVE-2011-3544

    CVE from 2011, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  587. Rank 597Oracle Java SE (JRE / JDK)

    CVE-2012-0507

    RansomwareCVE from 2012, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  588. Rank 598Oracle Java SE (JRE / JDK)

    CVE-2012-1723

    RansomwareCVE from 2012, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  589. Rank 599Oracle Java SE (JRE / JDK)

    CVE-2012-4681

    RansomwareCVE from 2012, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  590. Rank 600Adobe ColdFusion

    CVE-2013-0632

    CVE from 2013, added in 2022

    Adobe ColdFusion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  591. Rank 601Adobe Acrobat / Reader

    CVE-2013-3346

    CVE from 2013, added in 2022

    Adobe Reader and Acrobat Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  592. Rank 602Oracle Java SE (JRE / JDK)

    CVE-2015-2590

    CVE from 2015, added in 2022

    Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  593. Rank 603Cisco IOS / IOS XE

    CVE-2017-12240

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  594. Rank 604Cisco IOS / IOS XE

    CVE-2018-0151

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  595. Rank 605Exim

    CVE-2019-16928

    CVE from 2019, added in 2022

    Exim Out-of-bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  596. Rank 606Apache Tomcat

    CVE-2020-1938

    CVE from 2020, added in 2022

    Apache Tomcat Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  597. Rank 607Cisco RV routers (Small Business)

    CVE-2022-20699

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  598. Rank 608Cisco RV routers (Small Business)

    CVE-2022-20700

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  599. Rank 609Zabbix Frontend

    CVE-2022-23131

    Zabbix Frontend Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 22, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  600. Rank 610PHPUnit

    CVE-2017-9841

    CVE from 2017, added in 2022

    PHPUnit Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  601. Rank 611Adobe Commerce (Magento)

    CVE-2022-24086

    Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  602. Rank 612Microsoft Windows

    CVE-2015-1635

    CVE from 2015, added in 2022

    Microsoft HTTP.sys Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  603. Rank 613Apache ActiveMQ

    CVE-2016-3088

    CVE from 2016, added in 2022

    Apache ActiveMQ Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  604. Rank 614Apache Struts 1

    CVE-2017-9791

    CVE from 2017, added in 2022

    Apache Struts 1 Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  605. Rank 615Jenkins Core

    CVE-2018-1000861

    CVE from 2018, added in 2022

    Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  606. Rank 616Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-1776

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  607. Rank 617GNU Bash

    CVE-2014-6271

    CVE from 2014, added in 2022

    GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  608. Rank 618GNU Bash

    CVE-2014-7169

    CVE from 2014, added in 2022

    GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  609. Rank 619Intel Active Management Technology (AMT)

    CVE-2017-5689

    CVE from 2017, added in 2022

    Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  610. Rank 620Grandstream UCM6200

    CVE-2020-5722

    CVE from 2020, added in 2022

    Grandstream Networks UCM6200 Series SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  611. Rank 621SonicWall SMA 100 (ex-SRA)

    CVE-2021-20038

    Ransomware

    SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  612. Rank 622Apple iOS / iPadOS / macOS

    CVE-2022-22587

    Apple Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  613. Rank 623Apache Struts

    CVE-2012-0391

    CVE from 2012, added in 2022

    Apache Struts 2 Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  614. Rank 624Apache Airflow

    CVE-2020-13927

    CVE from 2020, added in 2022

    Apache Airflow's Experimental API Authentication Bypass

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  615. Rank 625F5 BIG-IP

    CVE-2021-22991

    F5 BIG-IP Traffic Management Microkernel Buffer Overflow

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  616. Rank 626Aviatrix Controller

    CVE-2021-40870

    Aviatrix Controller Unrestricted Upload of File

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  617. Rank 627IBM WebSphere Application Server

    CVE-2015-7450

    CVE from 2015, added in 2022

    IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  618. Rank 628PrimeTek PrimeFaces

    CVE-2017-1000486

    CVE from 2017, added in 2022

    Primetek Primefaces Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  619. Rank 629Exim

    CVE-2019-10149

    CVE from 2019, added in 2022

    Exim Mail Transfer Agent (MTA) Improper Input Validation

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  620. Rank 630Oracle WebLogic Server

    CVE-2019-2725

    RansomwareCVE from 2019, added in 2022

    Oracle WebLogic Server, Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  621. Rank 631Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2019-9670

    CVE from 2019, added in 2022

    Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  622. Rank 632Hikvision IP cameras and recorders (NVR/DVR)

    CVE-2021-36260

    Hikvision Improper Input Validation

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  623. Rank 633Red Hat JBoss Application Server / EAP

    CVE-2017-12149

    RansomwareCVE from 2017, added in 2021

    Red Hat JBoss Application Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.8 (critical)
  624. Rank 634Sonatype Nexus Repository

    CVE-2019-7238

    CVE from 2019, added in 2021

    Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.8 (critical)
  625. Rank 635Fuel CMS

    CVE-2020-17463

    Fuel CMS SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.8 (critical)
  626. Rank 636Realtek Router SDKs (Jungle, AP-Router)

    CVE-2021-35394

    Realtek Jungle SDK Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  627. Rank 637ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)

    CVE-2021-44515

    Zoho Desktop Central Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  628. Rank 638ManageEngine (Zoho) ServiceDesk Plus

    CVE-2021-37415

    Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  629. Rank 639ManageEngine (Zoho) ServiceDesk Plus

    CVE-2021-44077

    Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  630. Rank 640Oracle WebLogic Server

    CVE-2015-4852

    CVE from 2015, added in 2021

    Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  631. Rank 641Apache Shiro

    CVE-2016-4437

    CVE from 2016, added in 2021

    Apache Shiro Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  632. Rank 642Apache Struts

    CVE-2017-5638

    RansomwareCVE from 2017, added in 2021

    Apache Struts Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  633. Rank 643Microsoft IIS

    CVE-2017-7269

    CVE from 2017, added in 2021

    Microsoft Windows Server Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  634. Rank 644Progress Telerik UI for ASP.NET AJAX

    CVE-2017-9248

    CVE from 2017, added in 2021

    Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  635. Rank 645Cisco IOS / IOS XE

    CVE-2018-0171

    CVE from 2018, added in 2021

    Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  636. Rank 646Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13379

    RansomwareCVE from 2018, added in 2021

    Fortinet FortiOS SSL VPN Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  637. Rank 647Tenda Wi-Fi routers

    CVE-2018-14558

    CVE from 2018, added in 2021

    Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  638. Rank 648Adobe ColdFusion

    CVE-2018-15961

    CVE from 2018, added in 2021

    Adobe ColdFusion Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  639. Rank 649ThinkPHP

    CVE-2018-20062

    CVE from 2018, added in 2021

    ThinkPHP "noneCms" Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  640. Rank 650Adobe ColdFusion

    CVE-2018-4939

    CVE from 2018, added in 2021

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  641. Rank 651Exim

    CVE-2018-6789

    RansomwareCVE from 2018, added in 2021

    Exim Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  642. Rank 652Drupal Core

    CVE-2018-7600

    RansomwareCVE from 2018, added in 2021

    Drupal Core Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  643. Rank 653Microsoft SharePoint Server

    CVE-2019-0604

    RansomwareCVE from 2019, added in 2021

    Microsoft SharePoint Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  644. Rank 654Microsoft Windows

    CVE-2019-0708

    RansomwareCVE from 2019, added in 2021

    Microsoft Remote Desktop Services Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  645. Rank 655Atlassian Crowd

    CVE-2019-11580

    RansomwareCVE from 2019, added in 2021

    Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  646. Rank 656Citrix Workspace app / Receiver

    CVE-2019-11634

    RansomwareCVE from 2019, added in 2021

    Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  647. Rank 657SIMalliance Toolbox Browser

    CVE-2019-16256

    CVE from 2019, added in 2021

    SIMalliance Toolbox Browser Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  648. Rank 658vBulletin

    CVE-2019-16759

    CVE from 2019, added in 2021

    vBulletin PHP Module Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  649. Rank 659Progress Telerik UI for ASP.NET AJAX

    CVE-2019-18935

    RansomwareCVE from 2019, added in 2021

    Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  650. Rank 660Citrix NetScaler ADC / Gateway

    CVE-2019-19781

    RansomwareCVE from 2019, added in 2021

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  651. Rank 661Atlassian Confluence Server / Data Center

    CVE-2019-3396

    RansomwareCVE from 2019, added in 2021

    Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  652. Rank 662IBM Planning Analytics (TM1)

    CVE-2019-4716

    CVE from 2019, added in 2021

    IBM Planning Analytics Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  653. Rank 663VMware (Broadcom) ESXi

    CVE-2019-5544

    RansomwareCVE from 2019, added in 2021

    VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  654. Rank 664Microsoft .NET / Visual Studio

    CVE-2020-0646

    Microsoft .NET Framework Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  655. Rank 665SolarWinds Orion Platform

    CVE-2020-10148

    SolarWinds Orion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  656. Rank 666Sumavision Enhanced Multimedia Router (EMR)

    CVE-2020-10181

    Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  657. Rank 667ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)

    CVE-2020-10189

    Zoho ManageEngine Desktop Central File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  658. Rank 668Tenda Wi-Fi routers

    CVE-2020-10987

    Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  659. Rank 669SaltStack Salt

    CVE-2020-11651

    SaltStack Salt Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  660. Rank 670Sophos Firewall (SFOS, ex-XG)

    CVE-2020-12271

    Ransomware

    Sophos SFOS SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  661. Rank 671Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2020-12812

    Ransomware

    Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  662. Rank 672Oracle WebLogic Server

    CVE-2020-14750

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  663. Rank 673Oracle WebLogic Server

    CVE-2020-14882

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  664. Rank 674Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2020-15505

    Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  665. Rank 675SaltStack Salt

    CVE-2020-16846

    SaltStack Salt Shell Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  666. Rank 676vBulletin

    CVE-2020-17496

    vBulletin PHP Module Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  667. Rank 677Apache Struts

    CVE-2020-17530

    Apache Struts Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  668. Rank 678WordPress Plugins

    CVE-2020-25213

    WordPress File Manager Plugin Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  669. Rank 679D-Link NAS DNS (ShareCenter)

    CVE-2020-25506

    D-Link DNS-320 Device Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  670. Rank 680Oracle Coherence

    CVE-2020-2555

    Oracle Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  671. Rank 681NETGEAR Switches (GS, JGS, MS)

    CVE-2020-26919

    Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  672. Rank 682D-Link Routers (DIR, DWR, DSR)

    CVE-2020-29557

    D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  673. Rank 683Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2020-29583

    Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  674. Rank 684Cisco IP Phones

    CVE-2020-3161

    Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  675. Rank 685VMware (Broadcom) vCenter Server

    CVE-2020-3952

    VMware vCenter Server Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  676. Rank 686VMware (Broadcom) ESXi

    CVE-2020-3992

    Ransomware

    VMware ESXi OpenSLP Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  677. Rank 687IBM Data Risk Manager

    CVE-2020-4427

    IBM Data Risk Manager Security Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  678. Rank 688Unraid

    CVE-2020-5847

    Unraid Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  679. Rank 689F5 BIG-IP

    CVE-2020-5902

    Ransomware

    F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  680. Rank 690SAP Solution Manager

    CVE-2020-6207

    SAP Solution Manager Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  681. Rank 691Liferay Portal / DXP

    CVE-2020-7961

    Liferay Portal Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  682. Rank 692DrayTek Vigor (routers)

    CVE-2020-8515

    Multiple DrayTek Vigor Routers Web Management Page Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  683. Rank 693Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-8599

    Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  684. Rank 694PlaySMS

    CVE-2020-8644

    PlaySMS Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  685. Rank 695EyesOfNetwork

    CVE-2020-8657

    EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  686. Rank 696Cisco HyperFlex HX

    CVE-2021-1497

    Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  687. Rank 697Cisco HyperFlex HX

    CVE-2021-1498

    Cisco HyperFlex HX Data Platform Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  688. Rank 698Apple Safari / WebKit

    CVE-2021-1870

    Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  689. Rank 699Apple Safari / WebKit

    CVE-2021-1871

    Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  690. Rank 700SonicWall SMA 100 (ex-SRA)

    CVE-2021-20016

    Ransomware

    SonicWall SSLVPN SMA100 SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  691. Rank 701SonicWall Email Security

    CVE-2021-20021

    Ransomware

    SonicWall Email Security Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  692. Rank 702Arcadyan Buffalo Firmware

    CVE-2021-20090

    Arcadyan Buffalo Firmware Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  693. Rank 703VMware (Broadcom) vCenter Server

    CVE-2021-21972

    Ransomware

    VMware vCenter Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  694. Rank 704VMware (Broadcom) vCenter Server

    CVE-2021-21985

    Ransomware

    VMware vCenter Server Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  695. Rank 705VMware (Broadcom) vCenter Server

    CVE-2021-22005

    Ransomware

    VMware vCenter Server File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  696. Rank 706OpenText (Micro Focus) Operations Bridge Reporter (OBR)

    CVE-2021-22502

    Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  697. Rank 707F5 BIG-IP

    CVE-2021-22986

    Ransomware

    F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  698. Rank 708Atlassian Confluence Server / Data Center

    CVE-2021-26084

    Ransomware

    Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  699. Rank 709Microsoft Exchange Server

    CVE-2021-26855

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  700. Rank 710Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27101

    Ransomware

    Accellion FTA SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  701. Rank 711Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27103

    Ransomware

    Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  702. Rank 712Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27104

    Ransomware

    Accellion FTA OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  703. Rank 713Yealink Device Management

    CVE-2021-27561

    Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  704. Rank 714Kaseya VSA

    CVE-2021-30116

    Ransomware

    Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  705. Rank 715Tenda Wi-Fi routers

    CVE-2021-31755

    Tenda AC11 Router Stack Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  706. Rank 716Microsoft Exchange Server

    CVE-2021-34473

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  707. Rank 717Microsoft Exchange Server

    CVE-2021-34523

    Ransomware

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  708. Rank 718Realtek Router SDKs (Jungle, AP-Router)

    CVE-2021-35395

    Realtek AP-Router SDK Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  709. Rank 719ForgeRock Access Management (AM)

    CVE-2021-35464

    Ransomware

    ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  710. Rank 720Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38647

    Ransomware

    Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  711. Rank 721ManageEngine (Zoho) ADSelfService Plus

    CVE-2021-40539

    Ransomware

    Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  712. Rank 722Apache HTTP Server

    CVE-2021-41773

    Ransomware

    Apache HTTP Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  713. Rank 723Apache HTTP Server

    CVE-2021-42013

    Ransomware

    Apache HTTP Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  714. Rank 724BQE BillQuick Web Suite

    CVE-2021-42258

    Ransomware

    BQE BillQuick Web Suite SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  715. Rank 725Google Chrome / Chromium

    CVE-2024-7971

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 26, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  716. Rank 726Google Chrome / Chromium

    CVE-2024-5274

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 28, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  717. Rank 727Google Chrome / Chromium

    CVE-2024-4947

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  718. Rank 728Google Chrome / Chromium

    CVE-2024-4671

    Google Chromium Visuals Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  719. Rank 729Google Chrome / Chromium

    CVE-2023-6345

    Google Skia Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 30, 2023
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  720. Rank 730Google Chrome / Chromium

    CVE-2023-2136

    Google Chrome Skia Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  721. Rank 731Google Chrome / Chromium

    CVE-2022-4135

    Google Chromium GPU Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  722. Rank 732Google Chrome / Chromium

    CVE-2022-3075

    Google Chromium Mojo Insufficient Data Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  723. Rank 733Mozilla Firefox

    CVE-2022-26486

    Mozilla Firefox Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  724. Rank 734Google Chrome / Chromium

    CVE-2020-15999

    Google Chrome FreeType Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  725. Rank 735Google Chrome / Chromium

    CVE-2020-16010

    Google Chrome for Android UI Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.6 (critical)
  726. Rank 736Google Chrome / Chromium

    CVE-2020-16017

    Google Chrome Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.6 (critical)
  727. Rank 737Google Chrome / Chromium

    CVE-2021-30633

    Google Chromium Indexed DB API Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  728. Rank 738Google Chrome / Chromium

    CVE-2021-37973

    Google Chromium Portals Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  729. Rank 739Roundcube Webmail

    CVE-2024-42009

    RoundCube Webmail Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2025
    CISA deadline
    21 days
    CVSS severity
    9.3 (critical)
  730. Rank 740SAP NetWeaver

    CVE-2025-42999

    Ransomware

    SAP NetWeaver Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 15, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  731. Rank 741Apache HTTP Server

    CVE-2024-38475

    Apache HTTP Server Improper Escaping of Output Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  732. Rank 742Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2025-0108

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  733. Rank 743Mitel MiCollab

    CVE-2024-41713

    Ransomware

    Mitel MiCollab Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  734. Rank 744Palo Alto Networks Expedition

    CVE-2024-9465

    Palo Alto Networks Expedition SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  735. Rank 745PTZOptics PT30X-SDI/NDI Cameras

    CVE-2024-8956

    PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 4, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  736. Rank 746SolarWinds Web Help Desk

    CVE-2024-28987

    SolarWinds Web Help Desk Hardcoded Credential Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  737. Rank 747Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2024-21887

    Ransomware

    Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    12 days
    CVSS severity
    9.1 (critical)
  738. Rank 748Cisco ASA / Firepower (FTD)

    CVE-2023-20269

    Ransomware

    Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  739. Rank 749QNAP Photo Station

    CVE-2022-27593

    Ransomware

    QNAP Photo Station Externally Controlled Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  740. Rank 750Arcserve Unified Data Protection (UDP)

    CVE-2015-4068

    CVE from 2015, added in 2022

    Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  741. Rank 751October CMS

    CVE-2021-32648

    October CMS Improper Authentication

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    9.1 (critical)
  742. Rank 752MikroTik RouterOS

    CVE-2018-14847

    CVE from 2018, added in 2021

    MikroTik Router OS Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    182 days
    CVSS severity
    9.1 (critical)
  743. Rank 753Oracle Fusion Middleware

    CVE-2012-3152

    CVE from 2012, added in 2021

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  744. Rank 754VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2020-4006

    Multiple VMware Products Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  745. Rank 755IBM Data Risk Manager

    CVE-2020-4428

    IBM Data Risk Manager Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  746. Rank 756Dassault Systèmes DELMIA Apriso

    CVE-2025-5086

    Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 11, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  747. Rank 757Sitecore Experience Platform / Manager (XP / XM)

    CVE-2025-53690

    Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 4, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  748. Rank 758Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2023-34192

    CVE from 2023, added in 2025

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  749. Rank 759Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2025-0282

    Ransomware

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2025
    CISA deadline
    7 days
    CVSS severity
    9.0 (critical)
  750. Rank 760Apache Log4j

    CVE-2021-45046

    RansomwareCVE from 2021, added in 2023

    Apache Log4j2 Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2023
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  751. Rank 761Apache HTTP Server

    CVE-2021-40438

    Ransomware

    Apache HTTP Server-Side Request Forgery (SSRF)

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    14 days
    CVSS severity
    9.0 (critical)
  752. Rank 762Microsoft Hyper-V

    CVE-2020-1040

    Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.0 (critical)
  753. Rank 763Apple iOS / iPadOS / macOS

    CVE-2026-86950

    Hunt for compromise (CISA)

    Apple Multiple Products Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 29, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  754. Rank 764Google Android

    CVE-2025-48543

    Android Runtime Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 4, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  755. Rank 765TP-Link Range extenders and access points (TL-WA, RE)

    CVE-2020-24363

    CVE from 2020, added in 2025

    TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  756. Rank 766N-able N-central

    CVE-2025-8876

    N-able N-Central Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2025
    CISA deadline
    7 days
    CVSS severity
    8.8 (high)
  757. Rank 767Microsoft Office

    CVE-2007-0671

    CVE from 2007, added in 2025

    Microsoft Office Excel Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  758. Rank 768Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3893

    CVE from 2013, added in 2025

    Microsoft Internet Explorer Resource Management Errors Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  759. Rank 769RARLAB WinRAR

    CVE-2025-8088

    Ransomware

    RARLAB WinRAR Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  760. Rank 770D-Link DCS cameras

    CVE-2020-25079

    CVE from 2020, added in 2025

    D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  761. Rank 771D-Link DNR video recorders (NVR)

    CVE-2022-40799

    CVE from 2022, added in 2025

    D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  762. Rank 772PaperCut NG / MF

    CVE-2023-2533

    CVE from 2023, added in 2025

    PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 28, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  763. Rank 773Microsoft SharePoint Server

    CVE-2025-49704

    Ransomware

    Microsoft SharePoint Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    1 day
    CVSS severity
    8.8 (high)
  764. Rank 774Google Chrome / Chromium

    CVE-2025-6558

    Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  765. Rank 775TP-Link TL-WR (Wi-Fi routers)

    CVE-2023-33538

    CVE from 2023, added in 2025

    TP-Link Multiple Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 16, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  766. Rank 776Microsoft Windows

    CVE-2025-33053

    Microsoft Windows External Control of File Name or Path Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 10, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  767. Rank 777Google Chrome / Chromium

    CVE-2025-5419

    Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  768. Rank 778ASUS Routers (RT, GT, ZenWiFi)

    CVE-2023-39780

    CVE from 2023, added in 2025

    ASUS RT-AX55 Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  769. Rank 779Srimax Output Messenger

    CVE-2025-27920

    Srimax Output Messenger Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  770. Rank 780Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2025-4428

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  771. Rank 781Commvault Web Server

    CVE-2025-3928

    Commvault Web Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 28, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  772. Rank 782Sitecore Experience Platform / Manager (XP / XM)

    CVE-2019-9875

    CVE from 2019, added in 2025

    Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 26, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  773. Rank 783Advantive VeraCore

    CVE-2024-57968

    Advantive VeraCore Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  774. Rank 784Oracle Agile PLM

    CVE-2024-20953

    Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 24, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  775. Rank 785Zyxel Home gateways and routers (DSL, CPE)

    CVE-2024-40890

    Zyxel DSL CPE OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  776. Rank 786Zyxel Home gateways and routers (DSL, CPE)

    CVE-2024-40891

    Zyxel DSL CPE OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  777. Rank 787Trimble Cityworks

    CVE-2025-0994

    Trimble Cityworks Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 7, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  778. Rank 788Apple Safari / WebKit

    CVE-2024-44308

    Apple Multiple Products Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  779. Rank 789Microsoft Windows

    CVE-2024-49039

    Ransomware

    Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  780. Rank 790Ivanti Endpoint Manager (EPM)

    CVE-2024-29824

    Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 2, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  781. Rank 791Microsoft SQL Server

    CVE-2020-0618

    RansomwareCVE from 2020, added in 2024

    Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  782. Rank 792Microsoft Windows

    CVE-2024-43461

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  783. Rank 793Google Chrome / Chromium

    CVE-2024-7965

    Google Chromium V8 Inappropriate Implementation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 28, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  784. Rank 794Microsoft Office

    CVE-2024-38189

    Microsoft Project Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  785. Rank 795Microsoft Windows

    CVE-2018-0824

    CVE from 2018, added in 2024

    Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  786. Rank 796Google Chrome / Chromium

    CVE-2024-4761

    Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  787. Rank 797Microsoft Windows

    CVE-2024-30040

    Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  788. Rank 798Microsoft Windows

    CVE-2024-29988

    Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 30, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  789. Rank 799Google Chrome / Chromium

    CVE-2023-4762

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  790. Rank 800Apple Safari / WebKit

    CVE-2024-23222

    Apple Multiple Products WebKit Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 23, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  791. Rank 801Citrix NetScaler ADC / Gateway

    CVE-2023-6548

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    7 days
    CVSS severity
    8.8 (high)
  792. Rank 802Google Chrome / Chromium

    CVE-2024-0519

    Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  793. Rank 803Google Chrome / Chromium

    CVE-2023-7024

    Google Chromium WebRTC Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 2, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  794. Rank 804QNAP VioStor NVR

    CVE-2023-47565

    QNAP VioStor NVR OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 21, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  795. Rank 805FXC AE1021, AE1021PE

    CVE-2023-49897

    FXC AE1021, AE1021PE OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 21, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  796. Rank 806Apple Safari / WebKit

    CVE-2023-42917

    Apple Multiple Products WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 4, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  797. Rank 807Microsoft Windows

    CVE-2023-36025

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  798. Rank 808F5 BIG-IP

    CVE-2023-46748

    F5 BIG-IP Configuration Utility SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 31, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  799. Rank 809Progress WS_FTP Server

    CVE-2023-40044

    Ransomware

    Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 5, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  800. Rank 810Google Chrome / Chromium

    CVE-2023-5217

    Google Chromium libvpx Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 2, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  801. Rank 811Apple Safari / WebKit

    CVE-2023-41993

    Apple Multiple Products WebKit Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  802. Rank 812MinIO

    CVE-2023-28434

    MinIO Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 19, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  803. Rank 813Zyxel Home gateways and routers (DSL, CPE)

    CVE-2017-6884

    RansomwareCVE from 2017, added in 2023

    Zyxel EMG2926 Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  804. Rank 814Google Chrome / Chromium

    CVE-2023-4863

    Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 13, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  805. Rank 815Apple Safari / WebKit

    CVE-2023-37450

    Apple Multiple Products WebKit Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 13, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  806. Rank 816Microsoft Windows

    CVE-2023-32049

    Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  807. Rank 817Arm Mali GPU (pilote noyau)

    CVE-2021-29256

    CVE from 2021, added in 2023

    Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  808. Rank 818Apple Safari / WebKit

    CVE-2023-32435

    Apple Multiple Products WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  809. Rank 819Apple Safari / WebKit

    CVE-2023-32439

    Apple Multiple Products WebKit Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  810. Rank 820Google Chrome / Chromium

    CVE-2023-3079

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  811. Rank 821Apple Safari / WebKit

    CVE-2023-32373

    Apple Multiple Products WebKit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  812. Rank 822TP-Link Archer (Wi-Fi routers)

    CVE-2023-1389

    TP-Link Archer AX-21 Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  813. Rank 823Cisco IOS / IOS XE

    CVE-2017-6742

    CVE from 2017, added in 2023

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  814. Rank 824Google Chrome / Chromium

    CVE-2023-2033

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  815. Rank 825Apple Safari / WebKit

    CVE-2023-28205

    Apple Multiple Products WebKit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 10, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  816. Rank 826Veritas Backup Exec

    CVE-2021-27878

    RansomwareCVE from 2021, added in 2023

    Veritas Backup Exec Agent Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  817. Rank 827Google Chrome / Chromium

    CVE-2022-3038

    Google Chromium Network Service Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  818. Rank 828Arm Mali GPU (pilote noyau)

    CVE-2022-38181

    Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  819. Rank 829Apache Spark

    CVE-2022-33891

    Apache Spark Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  820. Rank 830Apple Safari / WebKit

    CVE-2023-23529

    Apple Multiple Products WebKit Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  821. Rank 831SugarCRM Sugar (Sell, Serve, Enterprise)

    CVE-2023-22952

    Multiple SugarCRM Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 2, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  822. Rank 832Microsoft Windows

    CVE-2023-21674

    Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  823. Rank 833TIBCO JasperReports

    CVE-2018-5430

    CVE from 2018, added in 2022

    TIBCO JasperReports Server Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 29, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  824. Rank 834Apple Safari / WebKit

    CVE-2022-42856

    Apple iOS Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 14, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  825. Rank 835Veeam Backup & Replication

    CVE-2022-26500

    Ransomware

    Veeam Backup & Replication Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  826. Rank 836Google Chrome / Chromium

    CVE-2022-4262

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 5, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  827. Rank 837Microsoft Windows

    CVE-2022-41128

    Microsoft Windows Scripting Languages Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    8.8 (high)
  828. Rank 838Google Chrome / Chromium

    CVE-2022-3723

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  829. Rank 839Atlassian Bitbucket Server / Data Center

    CVE-2022-36804

    Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  830. Rank 840Microsoft Exchange Server

    CVE-2022-41040

    Ransomware

    Microsoft Exchange Server Server-Side Request Forgery Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  831. Rank 841Linux Kernel

    CVE-2013-6282

    CVE from 2013, added in 2022

    Linux Kernel Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  832. Rank 842Google Chrome / Chromium

    CVE-2022-2294

    Ransomware

    WebRTC Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  833. Rank 843Microsoft Active Directory

    CVE-2022-26923

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  834. Rank 844Apple Safari / WebKit

    CVE-2022-32893

    Apple iOS and macOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  835. Rank 845SAP NetWeaver

    CVE-2021-38163

    SAP NetWeaver Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  836. Rank 846Microsoft Office

    CVE-2006-2492

    CVE from 2006, added in 2022

    Microsoft Word Malformed Object Pointer Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  837. Rank 847Adobe Acrobat / Reader

    CVE-2008-0655

    CVE from 2008, added in 2022

    Adobe Acrobat and Reader Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  838. Rank 848Adobe Acrobat / Reader

    CVE-2009-3953

    CVE from 2009, added in 2022

    Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  839. Rank 849Microsoft Windows

    CVE-2012-1889

    CVE from 2012, added in 2022

    Microsoft XML Core Services Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  840. Rank 850Google Chrome / Chromium

    CVE-2016-1646

    CVE from 2016, added in 2022

    Google Chromium V8 Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  841. Rank 851Google Chrome / Chromium

    CVE-2016-5198

    CVE from 2016, added in 2022

    Google Chromium V8 Out-of-Bounds Memory Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  842. Rank 852Google Chrome / Chromium

    CVE-2017-5030

    CVE from 2017, added in 2022

    Google Chromium V8 Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  843. Rank 853Google Chrome / Chromium

    CVE-2017-5070

    CVE from 2017, added in 2022

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  844. Rank 854Google Chrome / Chromium

    CVE-2018-17463

    CVE from 2018, added in 2022

    Google Chromium V8 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  845. Rank 855Google Chrome / Chromium

    CVE-2018-17480

    CVE from 2018, added in 2022

    Google Chromium V8 Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  846. Rank 856Adobe Acrobat / Reader

    CVE-2018-4990

    CVE from 2018, added in 2022

    Adobe Acrobat and Reader Double Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  847. Rank 857Google Chrome / Chromium

    CVE-2018-6065

    CVE from 2018, added in 2022

    Google Chromium V8 Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  848. Rank 858Cisco RV routers (Small Business)

    CVE-2019-15271

    CVE from 2019, added in 2022

    Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  849. Rank 859Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-2817

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  850. Rank 860Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-4123

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  851. Rank 861Microsoft Windows

    CVE-2014-4148

    CVE from 2014, added in 2022

    Microsoft Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  852. Rank 862Microsoft Windows

    CVE-2015-2360

    CVE from 2015, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  853. Rank 863Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2425

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  854. Rank 864Mozilla Firefox

    CVE-2015-4495

    CVE from 2015, added in 2022

    Mozilla Firefox Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  855. Rank 865Microsoft Windows

    CVE-2016-7256

    CVE from 2016, added in 2022

    Microsoft Windows Open Type Font Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  856. Rank 866Oracle Solaris

    CVE-2019-3010

    CVE from 2019, added in 2022

    Oracle Solaris Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  857. Rank 867Apple Safari / WebKit

    CVE-2016-4657

    CVE from 2016, added in 2022

    Apple iOS Webkit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  858. Rank 868Cisco ASA / Firepower (FTD)

    CVE-2016-6366

    CVE from 2016, added in 2022

    Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  859. Rank 869Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0149

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  860. Rank 870Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0210

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  861. Rank 871Mozilla Firefox

    CVE-2019-11707

    CVE from 2019, added in 2022

    Mozilla Firefox and Thunderbird Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  862. Rank 872Google Chrome / Chromium

    CVE-2019-13720

    CVE from 2019, added in 2022

    Google Chrome WebAudio Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  863. Rank 873WebKitGTK

    CVE-2019-8720

    CVE from 2019, added in 2022

    WebKitGTK Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  864. Rank 874Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-0322

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  865. Rank 875Apple Safari / WebKit

    CVE-2019-8506

    CVE from 2019, added in 2022

    Apple Multiple Products Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  866. Rank 876Apple Safari / WebKit

    CVE-2021-1789

    Apple Multiple Products Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  867. Rank 877Google Chrome / Chromium

    CVE-2022-1364

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  868. Rank 878Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2502

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  869. Rank 879Microsoft Active Directory

    CVE-2021-42287

    Ransomware

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  870. Rank 880WatchGuard Firebox / XTM (Fireware)

    CVE-2022-23176

    WatchGuard Firebox and XTM Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  871. Rank 881Mozilla Firefox

    CVE-2013-1690

    CVE from 2013, added in 2022

    Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  872. Rank 882Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-2551

    RansomwareCVE from 2013, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  873. Rank 883Microsoft Office

    CVE-2015-1770

    CVE from 2015, added in 2022

    Microsoft Office Uninitialized Memory Use Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  874. Rank 884Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2419

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  875. Rank 885Microsoft Windows

    CVE-2015-2426

    CVE from 2015, added in 2022

    Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  876. Rank 886Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-7200

    CVE from 2016, added in 2022

    Microsoft Edge Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  877. Rank 887Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-7201

    CVE from 2016, added in 2022

    Microsoft Edge Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  878. Rank 888Google Chrome / Chromium

    CVE-2022-1096

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  879. Rank 889Adobe Acrobat / Reader

    CVE-2009-0927

    CVE from 2009, added in 2022

    Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  880. Rank 890Microsoft Active Directory

    CVE-2014-6324

    CVE from 2014, added in 2022

    Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  881. Rank 891Microsoft Windows

    CVE-2014-6332

    CVE from 2014, added in 2022

    Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  882. Rank 892Microsoft Windows

    CVE-2017-0146

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows SMB Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  883. Rank 893Microsoft Windows

    CVE-2018-8414

    CVE from 2018, added in 2022

    Microsoft Windows Shell Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  884. Rank 894Microsoft Windows

    CVE-2019-0903

    CVE from 2019, added in 2022

    Microsoft GDI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  885. Rank 895Citrix SD-WAN

    CVE-2019-12991

    CVE from 2019, added in 2022

    Citrix SD-WAN and NetScaler Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  886. Rank 896Apache Kylin

    CVE-2020-1956

    CVE from 2020, added in 2022

    Apache Kylin OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  887. Rank 897NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2016-6277

    CVE from 2016, added in 2022

    NETGEAR Multiple Routers Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    8.8 (high)
  888. Rank 898Mozilla Firefox

    CVE-2022-26485

    Mozilla Firefox Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  889. Rank 899Oracle VirtualBox

    CVE-2008-3431

    CVE from 2008, added in 2022

    Oracle VirtualBox Insufficient Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  890. Rank 900Microsoft Office

    CVE-2012-1856

    CVE from 2012, added in 2022

    Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  891. Rank 901Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-1347

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  892. Rank 902Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3897

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  893. Rank 903Adobe Acrobat / Reader

    CVE-2014-0496

    CVE from 2014, added in 2022

    Adobe Reader and Acrobat Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  894. Rank 904Microsoft Office

    CVE-2015-2424

    CVE from 2015, added in 2022

    Microsoft PowerPoint Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  895. Rank 905Cisco IOS / IOS XE

    CVE-2017-6736

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  896. Rank 906Cisco IOS / IOS XE

    CVE-2017-6737

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  897. Rank 907Cisco IOS / IOS XE

    CVE-2017-6738

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  898. Rank 908Cisco IOS / IOS XE

    CVE-2017-6739

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  899. Rank 909Cisco IOS / IOS XE

    CVE-2017-6740

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  900. Rank 910Cisco IOS / IOS XE

    CVE-2017-6743

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  901. Rank 911Cisco IOS / IOS XE

    CVE-2017-6744

    CVE from 2017, added in 2022

    Cisco IOS Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  902. Rank 912Cisco IOS / IOS XE / IOS XR

    CVE-2018-0167

    CVE from 2018, added in 2022

    Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  903. Rank 913Microsoft Office

    CVE-2019-1297

    CVE from 2019, added in 2022

    Microsoft Excel Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  904. Rank 914Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0222

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  905. Rank 915Google Chrome / Chromium

    CVE-2022-0609

    Google Chromium Animation Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  906. Rank 916Apple Safari / WebKit

    CVE-2022-22620

    Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  907. Rank 917Microsoft Windows

    CVE-2017-0144

    RansomwareCVE from 2017, added in 2022

    Microsoft SMBv1 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  908. Rank 918Microsoft Windows

    CVE-2017-0145

    RansomwareCVE from 2017, added in 2022

    Microsoft SMBv1 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  909. Rank 919Microsoft Windows

    CVE-2017-8464

    CVE from 2017, added in 2022

    Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  910. Rank 920Apache Airflow

    CVE-2020-11978

    CVE from 2020, added in 2022

    Apache Airflow Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  911. Rank 921Drupal Core

    CVE-2020-13671

    CVE from 2020, added in 2022

    Drupal core Un-restricted Upload of File

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  912. Rank 922Nagios XI

    CVE-2021-25296

    Nagios XI OS Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  913. Rank 923Nagios XI

    CVE-2021-25297

    Nagios XI OS Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  914. Rank 924Nagios XI

    CVE-2021-25298

    Nagios XI OS Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  915. Rank 925Microsoft Windows

    CVE-2013-3900

    CVE from 2013, added in 2022

    Microsoft WinVerifyTrust function Remote Code Execution

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  916. Rank 926Google Chrome / Chromium

    CVE-2020-6572

    CVE from 2020, added in 2022

    Google Chrome Media Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  917. Rank 927FatPipe WARP, IPVPN, and MPVPN software

    CVE-2021-27860

    FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  918. Rank 928Google Chrome / Chromium

    CVE-2021-4102

    Google Chromium V8 Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 15, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  919. Rank 929Red Hat JBoss Seam

    CVE-2010-1871

    CVE from 2010, added in 2021

    Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    8.8 (high)
  920. Rank 930Microsoft Exchange Server

    CVE-2021-42321

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  921. Rank 931Microsoft Office

    CVE-2012-0158

    RansomwareCVE from 2012, added in 2021

    Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  922. Rank 932Microsoft Windows

    CVE-2014-1812

    RansomwareCVE from 2014, added in 2021

    Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  923. Rank 933Microsoft Windows

    CVE-2017-0143

    RansomwareCVE from 2017, added in 2021

    Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  924. Rank 934Symantec Messaging Gateway

    CVE-2017-6327

    CVE from 2017, added in 2021

    Symantec Messaging Gateway Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  925. Rank 935DotNetNuke (DNN)

    CVE-2017-9822

    RansomwareCVE from 2017, added in 2021

    DotNetNuke (DNN) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  926. Rank 936Microsoft Office

    CVE-2018-0798

    CVE from 2018, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  927. Rank 937Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0541

    CVE from 2019, added in 2021

    Microsoft MSHTML Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  928. Rank 938Nagios XI

    CVE-2019-15949

    CVE from 2019, added in 2021

    Nagios XI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  929. Rank 939Mozilla Firefox

    CVE-2019-17026

    CVE from 2019, added in 2021

    Mozilla Firefox And Thunderbird Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  930. Rank 940Atlassian Confluence Server / Data Center

    CVE-2019-3398

    CVE from 2019, added in 2021

    Atlassian Confluence Server and Data Center Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  931. Rank 941ThinkPHP

    CVE-2019-9082

    CVE from 2019, added in 2021

    ThinkPHP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  932. Rank 942Microsoft Exchange Server

    CVE-2020-0688

    Ransomware

    Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  933. Rank 943Sonatype Nexus Repository

    CVE-2020-10199

    Sonatype Nexus Repository Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  934. Rank 944Microsoft Windows

    CVE-2020-1020

    Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  935. Rank 945rConfig

    CVE-2020-10221

    rConfig OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  936. Rank 946Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-1380

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  937. Rank 947Google Chrome / Chromium

    CVE-2020-16009

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  938. Rank 948Google Chrome / Chromium

    CVE-2020-16013

    Google Chromium V8 Incorrect Implementation Vulnerabililty

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  939. Rank 949Microsoft Exchange Server

    CVE-2020-17144

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  940. Rank 950Cisco IOS XR

    CVE-2020-3118

    Cisco IOS XR Software Discovery Protocol Format String Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  941. Rank 951Amcrest Cameras and Network Video Recorder (NVR)

    CVE-2020-5735

    Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  942. Rank 952Google Chrome / Chromium

    CVE-2020-6418

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  943. Rank 953Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-8467

    Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  944. Rank 954Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-8468

    Trend Micro Multiple Products Content Validation Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  945. Rank 955Apple iOS / iPadOS

    CVE-2020-9818

    Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  946. Rank 956Adobe Acrobat / Reader

    CVE-2021-21017

    Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  947. Rank 957Google Chrome / Chromium

    CVE-2021-21148

    Google Chromium V8 Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  948. Rank 958Google Chrome / Chromium

    CVE-2021-21166

    Google Chromium Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  949. Rank 959Google Chrome / Chromium

    CVE-2021-21193

    Google Chromium Blink Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  950. Rank 960Google Chrome / Chromium

    CVE-2021-21206

    Google Chromium Blink Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  951. Rank 961Google Chrome / Chromium

    CVE-2021-21220

    Google Chromium V8 Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  952. Rank 962Google Chrome / Chromium

    CVE-2021-21224

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  953. Rank 963Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22894

    Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  954. Rank 964Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22899

    Ivanti Pulse Connect Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  955. Rank 965Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-26411

    Ransomware

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  956. Rank 966Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-27085

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  957. Rank 967Adobe Acrobat / Reader

    CVE-2021-28550

    Adobe Acrobat and Reader Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  958. Rank 968Arm Mali GPU (pilote noyau)

    CVE-2021-28663

    Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  959. Rank 969Arm Mali GPU (pilote noyau)

    CVE-2021-28664

    Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  960. Rank 970Google Chrome / Chromium

    CVE-2021-30551

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  961. Rank 971Google Chrome / Chromium

    CVE-2021-30554

    Google Chromium WebGL Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  962. Rank 972Google Chrome / Chromium

    CVE-2021-30563

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  963. Rank 973Google Chrome / Chromium

    CVE-2021-30632

    Google Chromium V8 Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  964. Rank 974Apple Safari / WebKit

    CVE-2021-30661

    Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  965. Rank 975Apple Safari / WebKit

    CVE-2021-30663

    Apple Multiple Products WebKit Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  966. Rank 976Apple Safari / WebKit

    CVE-2021-30665

    Apple Multiple Products WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  967. Rank 977Apple Safari / WebKit

    CVE-2021-30666

    Apple iOS WebKit Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  968. Rank 978Apple Safari / WebKit

    CVE-2021-30761

    Apple iOS WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  969. Rank 979Apple Safari / WebKit

    CVE-2021-30762

    Apple iOS WebKit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  970. Rank 980Apple Safari / WebKit

    CVE-2021-30858

    Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  971. Rank 981Microsoft Windows

    CVE-2021-33742

    Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  972. Rank 982Microsoft Windows

    CVE-2021-34448

    Microsoft Windows Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  973. Rank 983Microsoft Windows

    CVE-2021-34527

    Ransomware

    Microsoft Windows Print Spooler Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  974. Rank 984Trend Micro Apex One (ex-OfficeScan)

    CVE-2021-36741

    Trend Micro Multiple Products Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  975. Rank 985Google Chrome / Chromium

    CVE-2021-37975

    Google Chromium V8 Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  976. Rank 986Google Chrome / Chromium

    CVE-2021-38003

    Google Chromium V8 Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  977. Rank 987Cisco ASA / Firepower (FTD)

    CVE-2025-20362

    Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2025
    CISA deadline
    1 day
    CVSS severity
    8.6 (high)
  978. Rank 988Qualcomm Snapdragon (chipsets and drivers)

    CVE-2025-21479

    Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 3, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  979. Rank 989Qualcomm Snapdragon (chipsets and drivers)

    CVE-2025-21480

    Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 3, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  980. Rank 990reviewdog action-setup GitHub Action

    CVE-2025-30154

    reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 24, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  981. Rank 991NAKIVO Backup and Replication

    CVE-2024-48248

    NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  982. Rank 992tj-actions changed-files GitHub Action

    CVE-2025-30066

    tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 18, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  983. Rank 993Check Point Quantum Security Gateway

    CVE-2024-24919

    Ransomware

    Check Point Quantum Security Gateways Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 30, 2024
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  984. Rank 994Cisco ASA / Firepower (FTD)

    CVE-2024-20353

    Cisco ASA and FTD Denial of Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    8.6 (high)
  985. Rank 995Apple Safari / WebKit

    CVE-2023-32409

    Apple Multiple Products WebKit Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2023
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  986. Rank 996Apple iOS / iPadOS / macOS

    CVE-2023-28206

    Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 10, 2023
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  987. Rank 997Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2022-0028

    Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 22, 2022
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  988. Rank 998Cisco IOS / IOS XE

    CVE-2018-0155

    CVE from 2018, added in 2022

    Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  989. Rank 999Cisco IOS / IOS XE

    CVE-2018-0158

    CVE from 2018, added in 2022

    Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  990. Rank 1000Cisco IOS / IOS XE

    CVE-2018-0172

    CVE from 2018, added in 2022

    Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  991. Rank 1001Cisco IOS / IOS XE

    CVE-2018-0173

    CVE from 2018, added in 2022

    Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  992. Rank 1002Cisco IOS / IOS XE

    CVE-2018-0174

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  993. Rank 1003Cisco IOS XR

    CVE-2020-3566

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.6 (high)
  994. Rank 1004Cisco IOS XR

    CVE-2020-3569

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.6 (high)
  995. Rank 1005XStream

    CVE-2021-39144

    CVE from 2021, added in 2023

    XStream Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2023
    CISA deadline
    21 days
    CVSS severity
    8.5 (high)
  996. Rank 1006ImageMagick

    CVE-2016-3714

    CVE from 2016, added in 2024

    ImageMagick Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 9, 2024
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  997. Rank 1007Linux Kernel

    CVE-2022-0185

    CVE from 2022, added in 2024

    Linux Kernel Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  998. Rank 1008Justice AV Solutions (JAVS) JAVS Viewer

    CVE-2024-4978

    Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 29, 2024
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  999. Rank 1009Microsoft Windows

    CVE-2023-29360

    Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 29, 2024
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  1000. Rank 1010Linux Kernel

    CVE-2013-2094

    CVE from 2013, added in 2022

    Linux Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  1001. Rank 1011Qualcomm Snapdragon (chipsets and drivers)

    CVE-2013-2597

    CVE from 2013, added in 2022

    Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  1002. Rank 1012Google Chrome / Chromium

    CVE-2025-2783

    Google Chromium Mojo Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 27, 2025
    CISA deadline
    21 days
    CVSS severity
    8.3 (high)
  1003. Rank 1013VMware (Broadcom) ESXi

    CVE-2025-22224

    VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2025
    CISA deadline
    21 days
    CVSS severity
    8.2 (high)
  1004. Rank 1014VMware (Broadcom) ESXi

    CVE-2025-22225

    Ransomware

    VMware ESXi Arbitrary Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2025
    CISA deadline
    21 days
    CVSS severity
    8.2 (high)
  1005. Rank 1015Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2024-21893

    Ransomware

    Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 31, 2024
    CISA deadline
    2 days
    CVSS severity
    8.2 (high)
  1006. Rank 1016Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2023-46805

    Ransomware

    Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    12 days
    CVSS severity
    8.2 (high)
  1007. Rank 1017Meta WhatsApp

    CVE-2019-18426

    CVE from 2019, added in 2022

    WhatsApp Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.2 (high)
  1008. Rank 1018Microsoft Windows

    CVE-2015-2546

    RansomwareCVE from 2015, added in 2022

    Microsoft Win32k Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    8.2 (high)
  1009. Rank 1019Google Chrome / Chromium

    CVE-2025-6554

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1010. Rank 1020FreeType

    CVE-2025-27363

    FreeType Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1011. Rank 1021Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-24472

    Ransomware

    Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 18, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1012. Rank 1022Craft CMS

    CVE-2025-23209

    Craft CMS Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 20, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1013. Rank 1023Acclaim Systems USAHERDS

    CVE-2021-44207

    CVE from 2021, added in 2024

    Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 23, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1014. Rank 1024Microsoft Windows

    CVE-2024-43573

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 8, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1015. Rank 1025Microsoft Windows

    CVE-2024-21412

    Ransomware

    Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 13, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1016. Rank 1026Laravel Framework

    CVE-2018-15133

    CVE from 2018, added in 2024

    Laravel Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1017. Rank 1027Veritas Backup Exec

    CVE-2021-27876

    RansomwareCVE from 2021, added in 2023

    Veritas Backup Exec Agent File Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1018. Rank 1028NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-5521

    CVE from 2017, added in 2022

    NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1019. Rank 1029Microsoft Internet Explorer / Edge (legacy)

    CVE-2012-4969

    CVE from 2012, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.1 (high)
  1020. Rank 1030Microsoft Windows

    CVE-2017-0148

    RansomwareCVE from 2017, added in 2022

    Microsoft SMBv1 Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 6, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1021. Rank 1031Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0037

    CVE from 2017, added in 2022

    Microsoft Edge and Internet Explorer Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1022. Rank 1032Elastic Elasticsearch

    CVE-2014-3120

    CVE from 2014, added in 2022

    Elasticsearch Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1023. Rank 1033Apache Tomcat

    CVE-2017-12615

    RansomwareCVE from 2017, added in 2022

    Apache Tomcat on Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1024. Rank 1034Apache Tomcat

    CVE-2017-12617

    CVE from 2017, added in 2022

    Apache Tomcat Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1025. Rank 1035VMware (Broadcom) SD-WAN (VeloCloud)

    CVE-2018-6961

    CVE from 2018, added in 2022

    VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1026. Rank 1036Drupal Core

    CVE-2019-6340

    CVE from 2019, added in 2022

    Drupal Core Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  1027. Rank 1037Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2019-1579

    RansomwareCVE from 2019, added in 2022

    Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  1028. Rank 1038Embedthis GoAhead

    CVE-2017-17562

    CVE from 2017, added in 2021

    Embedthis GoAhead Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    8.1 (high)
  1029. Rank 1039Apache Struts

    CVE-2017-9805

    CVE from 2017, added in 2021

    Apache Struts Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  1030. Rank 1040Apache Struts

    CVE-2018-11776

    CVE from 2018, added in 2021

    Apache Struts Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  1031. Rank 1041Microsoft Windows

    CVE-2020-0601

    Microsoft Windows CryptoAPI Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  1032. Rank 1042Mozilla Firefox

    CVE-2020-6819

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  1033. Rank 1043Mozilla Firefox

    CVE-2020-6820

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  1034. Rank 1044Citrix Session Recording

    CVE-2024-8068

    Citrix Session Recording Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2025
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  1035. Rank 1045Citrix Session Recording

    CVE-2024-8069

    Citrix Session Recording Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2025
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  1036. Rank 1046Git

    CVE-2025-48384

    Git Link Following Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2025
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  1037. Rank 1047Microsoft Exchange Server

    CVE-2022-41082

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  1038. Rank 1048Cisco IOS / IOS XE / IOS XR

    CVE-2018-0175

    CVE from 2018, added in 2022

    Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  1039. Rank 1049Cisco RV routers (Small Business)

    CVE-2022-20703

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  1040. Rank 1050Cisco RV routers (Small Business)

    CVE-2022-20708

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  1041. Rank 1051Linux Kernel

    CVE-2025-38352

    Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1042. Rank 1052N-able N-central

    CVE-2025-8875

    N-able N-Central Insecure Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2025
    CISA deadline
    7 days
    CVSS severity
    7.8 (high)
  1043. Rank 1053Linux Kernel

    CVE-2023-0386

    CVE from 2023, added in 2025

    Linux Kernel Improper Ownership Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 17, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1044. Rank 1054Microsoft Windows

    CVE-2025-30400

    Microsoft Windows DWM Core Library Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1045. Rank 1055Microsoft Windows

    CVE-2025-32701

    Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1046. Rank 1056Microsoft Windows

    CVE-2025-32706

    Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1047. Rank 1057Microsoft Windows

    CVE-2025-32709

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1048. Rank 1058Linux Kernel

    CVE-2024-53197

    Linux Kernel Out-of-Bounds Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 9, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1049. Rank 1059Microsoft Windows

    CVE-2025-29824

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 8, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1050. Rank 1060Microsoft Windows

    CVE-2025-24985

    Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1051. Rank 1061Microsoft Windows

    CVE-2025-24993

    Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1052. Rank 1062Microsoft Windows

    CVE-2018-8639

    RansomwareCVE from 2018, added in 2025

    Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1053. Rank 1063Microsoft Windows

    CVE-2025-21418

    Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1054. Rank 1064Audinate Dante Discovery

    CVE-2022-23748

    CVE from 2022, added in 2025

    Dante Discovery Process Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1055. Rank 1065Linux Kernel

    CVE-2024-53104

    Linux Kernel Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 5, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1056. Rank 1066Microsoft Windows

    CVE-2025-21333

    Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1057. Rank 1067Microsoft Windows

    CVE-2025-21334

    Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1058. Rank 1068Microsoft Windows

    CVE-2025-21335

    Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1059. Rank 1069Microsoft Windows

    CVE-2024-35250

    Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1060. Rank 1070Microsoft Windows

    CVE-2024-49138

    Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1061. Rank 1071Qualcomm Snapdragon (chipsets and drivers)

    CVE-2024-43047

    Qualcomm Multiple Chipsets Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 8, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1062. Rank 1072Microsoft Windows

    CVE-2024-43572

    Microsoft Windows Management Console Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 8, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1063. Rank 1073Microsoft Windows

    CVE-2024-38014

    Microsoft Windows Installer Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 10, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1064. Rank 1074Linux Kernel

    CVE-2017-1000253

    RansomwareCVE from 2017, added in 2024

    Linux Kernel PIE Stack Buffer Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1065. Rank 1075Kingsoft WPS Office

    CVE-2024-7262

    Kingsoft WPS Office Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1066. Rank 1076Microsoft Windows

    CVE-2024-38107

    Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1067. Rank 1077Microsoft Windows

    CVE-2024-38193

    Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1068. Rank 1078Google Android

    CVE-2024-36971

    Android Kernel Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 7, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1069. Rank 1079Microsoft Windows

    CVE-2024-38080

    Microsoft Windows Hyper-V Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1070. Rank 1080Linux Kernel

    CVE-2022-2586

    CVE from 2022, added in 2024

    Linux Kernel Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 26, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1071. Rank 1081Microsoft Windows

    CVE-2024-26169

    Ransomware

    Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1072. Rank 1082Google Pixel

    CVE-2024-32896

    Android Pixel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1073. Rank 1083Arm Mali GPU (pilote noyau)

    CVE-2024-4610

    Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 12, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1074. Rank 1084Linux Kernel

    CVE-2024-1086

    Ransomware

    Linux Kernel Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 30, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1075. Rank 1085Microsoft Windows

    CVE-2024-30051

    Ransomware

    Microsoft DWM Core Library Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1076. Rank 1086Microsoft Windows

    CVE-2022-38028

    CVE from 2022, added in 2024

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 23, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1077. Rank 1087Google Pixel

    CVE-2024-29748

    Android Pixel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1078. Rank 1088Apple iOS / iPadOS / macOS

    CVE-2024-23225

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 6, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1079. Rank 1089Apple iOS / iPadOS / macOS

    CVE-2024-23296

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 6, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1080. Rank 1090Microsoft Windows

    CVE-2024-21338

    Ransomware

    Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1081. Rank 1091Apple iOS / iPadOS / macOS

    CVE-2023-41990

    Apple Multiple Products Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1082. Rank 1092Spreadsheet::ParseExcel

    CVE-2023-7101

    Spreadsheet::ParseExcel Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 2, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1083. Rank 1093Qualcomm Snapdragon (chipsets and drivers)

    CVE-2022-22071

    Qualcomm Multiple Chipsets Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 5, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1084. Rank 1094Qualcomm Snapdragon (chipsets and drivers)

    CVE-2023-33063

    Qualcomm Multiple Chipsets Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 5, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1085. Rank 1095Qualcomm Snapdragon (chipsets and drivers)

    CVE-2023-33106

    Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 5, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1086. Rank 1096Qualcomm Snapdragon (chipsets and drivers)

    CVE-2023-33107

    Qualcomm Multiple Chipsets Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 5, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1087. Rank 1097GNU C Library (glibc)

    CVE-2023-4911

    GNU C Library Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1088. Rank 1098Microsoft Windows

    CVE-2023-36033

    Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1089. Rank 1099Microsoft Windows

    CVE-2023-36036

    Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1090. Rank 1100Adobe Acrobat / Reader

    CVE-2023-21608

    Adobe Acrobat and Reader Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1091. Rank 1101Apple iOS / iPadOS

    CVE-2023-42824

    Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 5, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1092. Rank 1102Apple iOS / iPadOS / macOS

    CVE-2023-41992

    Apple Multiple Products Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1093. Rank 1103Samsung Mobile Devices (Galaxy)

    CVE-2022-22265

    Samsung Mobile Devices Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1094. Rank 1104Adobe Acrobat / Reader

    CVE-2023-26369

    Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1095. Rank 1105Google Android

    CVE-2023-35674

    Android Framework Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 13, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1096. Rank 1106Microsoft Windows

    CVE-2023-36802

    Microsoft Streaming Service Proxy Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 12, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1097. Rank 1107Apple iOS / iPadOS

    CVE-2023-41061

    Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1098. Rank 1108Apple iOS / iPadOS / macOS

    CVE-2023-41064

    Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1099. Rank 1109RARLAB WinRAR

    CVE-2023-38831

    Ransomware

    RARLAB WinRAR Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 24, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1100. Rank 1110Microsoft Windows

    CVE-2023-32046

    Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1101. Rank 1111Microsoft Windows

    CVE-2023-36874

    Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1102. Rank 1112D-Link Access points (DAP, DWL)

    CVE-2019-20500

    CVE from 2019, added in 2023

    D-Link DWL-2600AP Access Point Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1103. Rank 1113Samsung Mobile Devices (Galaxy)

    CVE-2021-25487

    CVE from 2021, added in 2023

    Samsung Mobile Devices Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1104. Rank 1114Apple iOS / iPadOS / macOS

    CVE-2023-32434

    Apple Multiple Products Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1105. Rank 1115Microsoft Windows

    CVE-2016-0165

    CVE from 2016, added in 2023

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1106. Rank 1116Red Hat Polkit

    CVE-2021-3560

    CVE from 2021, added in 2023

    Red Hat Polkit Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1107. Rank 1117Microsoft Windows

    CVE-2023-29336

    Microsoft Win32K Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 9, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1108. Rank 1118Apple macOS (OS X)

    CVE-2019-8526

    CVE from 2019, added in 2023

    Apple macOS Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1109. Rank 1119Google Android

    CVE-2023-20963

    Android Framework Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1110. Rank 1120Microsoft Windows

    CVE-2023-28252

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1111. Rank 1121Microsoft Windows

    CVE-2019-1388

    RansomwareCVE from 2019, added in 2023

    Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1112. Rank 1122Apple iOS / iPadOS / macOS

    CVE-2021-30900

    CVE from 2021, added in 2023

    Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1113. Rank 1123Arm Mali GPU (pilote noyau)

    CVE-2022-22706

    Arm Mali GPU Kernel Driver Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1114. Rank 1124Microsoft Windows

    CVE-2023-21823

    Microsoft Windows Graphic Component Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1115. Rank 1125Microsoft Windows

    CVE-2023-23376

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1116. Rank 1126Intel Ethernet Diagnostics Driver for Windows

    CVE-2015-2291

    RansomwareCVE from 2015, added in 2023

    Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1117. Rank 1127Microsoft Windows

    CVE-2022-41073

    Ransomware

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    7.8 (high)
  1118. Rank 1128Microsoft Windows

    CVE-2022-41125

    Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    7.8 (high)
  1119. Rank 1129Apple iOS / iPadOS

    CVE-2022-42827

    Apple iOS and iPadOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1120. Rank 1130GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19320

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1121. Rank 1131GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19321

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1122. Rank 1132GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19322

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1123. Rank 1133Cisco AnyConnect Secure Mobility Client

    CVE-2020-3433

    RansomwareCVE from 2020, added in 2022

    Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1124. Rank 1134Linux Kernel

    CVE-2021-3493

    Linux Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 20, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1125. Rank 1135Microsoft Windows

    CVE-2022-41033

    Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1126. Rank 1136Microsoft Windows

    CVE-2010-2568

    CVE from 2010, added in 2022

    Microsoft Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1127. Rank 1137Linux Kernel

    CVE-2013-2596

    CVE from 2013, added in 2022

    Linux Kernel Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1128. Rank 1138Apple iOS / iPadOS / macOS

    CVE-2022-32917

    Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 14, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1129. Rank 1139Microsoft Windows

    CVE-2022-37969

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 14, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1130. Rank 1140Google Android

    CVE-2011-1823

    CVE from 2011, added in 2022

    Android OS Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1131. Rank 1141PEAR Archive_Tar

    CVE-2020-28949

    CVE from 2020, added in 2022

    PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1132. Rank 1142Microsoft Windows

    CVE-2022-21971

    Microsoft Windows Runtime Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1133. Rank 1143Apple iOS / iPadOS / macOS

    CVE-2022-32894

    Apple iOS and macOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1134. Rank 1144Microsoft Windows

    CVE-2022-34713

    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 9, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1135. Rank 1145Microsoft Windows

    CVE-2022-22047

    Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 12, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1136. Rank 1146Apple iOS / iPadOS / macOS

    CVE-2018-4344

    CVE from 2018, added in 2022

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1137. Rank 1147Apple iOS / iPadOS / macOS

    CVE-2019-8605

    CVE from 2019, added in 2022

    Apple Multiple Products Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1138. Rank 1148Apple iOS / iPadOS / macOS

    CVE-2020-3837

    CVE from 2020, added in 2022

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1139. Rank 1149Apple iOS / iPadOS

    CVE-2020-9907

    CVE from 2020, added in 2022

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1140. Rank 1150Apple iOS / iPadOS

    CVE-2021-30983

    Apple iOS and iPadOS Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1141. Rank 1151Red Hat Polkit

    CVE-2021-4034

    Ransomware

    Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1142. Rank 1152Microsoft Windows

    CVE-2022-30190

    Ransomware

    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 14, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1143. Rank 1153Adobe Acrobat / Reader

    CVE-2007-5659

    CVE from 2007, added in 2022

    Adobe Acrobat and Reader Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1144. Rank 1154Microsoft Office

    CVE-2009-0557

    CVE from 2009, added in 2022

    Microsoft Office Object Record Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1145. Rank 1155Microsoft Office

    CVE-2009-0563

    CVE from 2009, added in 2022

    Microsoft Office Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1146. Rank 1156Adobe Flash Player

    CVE-2009-1862

    CVE from 2009, added in 2022

    Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1147. Rank 1157Adobe Acrobat / Reader

    CVE-2009-4324

    CVE from 2009, added in 2022

    Adobe Acrobat and Reader Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1148. Rank 1158Microsoft Office

    CVE-2010-2572

    CVE from 2010, added in 2022

    Microsoft PowerPoint Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1149. Rank 1159Microsoft Windows

    CVE-2012-0151

    CVE from 2012, added in 2022

    Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1150. Rank 1160Microsoft Office

    CVE-2013-1331

    CVE from 2013, added in 2022

    Microsoft Office Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1151. Rank 1161Linux Kernel

    CVE-2014-3153

    CVE from 2014, added in 2022

    Linux Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1152. Rank 1162Microsoft Windows

    CVE-2014-4077

    CVE from 2014, added in 2022

    Microsoft IME Japanese Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1153. Rank 1163Microsoft Windows

    CVE-2015-0016

    CVE from 2015, added in 2022

    Microsoft Windows TS WebProxy Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1154. Rank 1164Microsoft Windows

    CVE-2015-1671

    CVE from 2015, added in 2022

    Microsoft Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1155. Rank 1165Microsoft Windows

    CVE-2015-6175

    CVE from 2015, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1156. Rank 1166Microsoft Windows

    CVE-2016-3393

    CVE from 2016, added in 2022

    Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1157. Rank 1167Apple iOS / iPadOS

    CVE-2016-4656

    CVE from 2016, added in 2022

    Apple iOS Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1158. Rank 1168Cisco ASA / Firepower (FTD)

    CVE-2016-6367

    CVE from 2016, added in 2022

    Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1159. Rank 1169Microsoft Windows

    CVE-2017-0005

    CVE from 2017, added in 2022

    Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1160. Rank 1170Artifex Ghostscript

    CVE-2017-8291

    CVE from 2017, added in 2022

    Artifex Ghostscript Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1161. Rank 1171Microsoft Windows

    CVE-2018-8611

    CVE from 2018, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1162. Rank 1172Microsoft Windows

    CVE-2018-8589

    CVE from 2018, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1163. Rank 1173Microsoft Windows

    CVE-2019-0880

    CVE from 2019, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1164. Rank 1174Microsoft Windows

    CVE-2019-1130

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1165. Rank 1175Microsoft Windows

    CVE-2019-1385

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1166. Rank 1176Apple iOS / iPadOS / macOS

    CVE-2019-7286

    CVE from 2019, added in 2022

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1167. Rank 1177Apple iOS / iPadOS

    CVE-2019-7287

    CVE from 2019, added in 2022

    Apple iOS Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1168. Rank 1178Microsoft Windows

    CVE-2020-0638

    RansomwareCVE from 2020, added in 2022

    Microsoft Update Notification Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1169. Rank 1179Microsoft Windows

    CVE-2020-1027

    CVE from 2020, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1170. Rank 1180Google Android

    CVE-2021-1048

    Android Kernel Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1171. Rank 1181Apple iOS / iPadOS / macOS

    CVE-2021-30883

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1172. Rank 1182Microsoft Windows

    CVE-2014-4113

    CVE from 2014, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1173. Rank 1183Microsoft Windows

    CVE-2021-40450

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1174. Rank 1184Microsoft Windows

    CVE-2021-41357

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1175. Rank 1185Linux Kernel

    CVE-2022-0847

    Linux Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1176. Rank 1186Microsoft Windows

    CVE-2022-22718

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1177. Rank 1187VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2022-22960

    VMware Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1178. Rank 1188Microsoft Windows

    CVE-2022-24521

    Ransomware

    Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1179. Rank 1189Google Pixel

    CVE-2021-39793

    Google Pixel Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1180. Rank 1190Sudo

    CVE-2021-3156

    Sudo Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 6, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1181. Rank 1191Apple macOS (OS X)

    CVE-2022-22675

    Apple macOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1182. Rank 1192Dell dbutil Driver

    CVE-2021-21551

    Dell dbutil Driver Insufficient Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1183. Rank 1193Microsoft Windows

    CVE-2021-34484

    Microsoft Windows User Profile Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1184. Rank 1194Microsoft Windows

    CVE-2010-4398

    CVE from 2010, added in 2022

    Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    24 days
    CVSS severity
    7.8 (high)
  1185. Rank 1195Microsoft Windows

    CVE-2011-2005

    CVE from 2011, added in 2022

    Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1186. Rank 1196Microsoft Office

    CVE-2012-2539

    CVE from 2012, added in 2022

    Microsoft Word Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1187. Rank 1197Microsoft Windows

    CVE-2013-3660

    CVE from 2013, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1188. Rank 1198Microsoft Windows

    CVE-2016-0040

    CVE from 2016, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1189. Rank 1199Microsoft Windows

    CVE-2016-0151

    RansomwareCVE from 2016, added in 2022

    Microsoft Windows CSRSS Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1190. Rank 1200Microsoft Windows

    CVE-2018-8405

    RansomwareCVE from 2018, added in 2022

    Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1191. Rank 1201Microsoft Windows

    CVE-2018-8406

    RansomwareCVE from 2018, added in 2022

    Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1192. Rank 1202Microsoft Windows

    CVE-2018-8440

    RansomwareCVE from 2018, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1193. Rank 1203Microsoft Windows

    CVE-2021-34486

    Microsoft Windows Event Tracing Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1194. Rank 1204Microsoft Office

    CVE-2021-38646

    Ransomware

    Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1195. Rank 1205Exim

    CVE-2010-4345

    CVE from 2010, added in 2022

    Exim Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1196. Rank 1206Microsoft Windows

    CVE-2022-21999

    Ransomware

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1197. Rank 1207Microsoft Windows

    CVE-2016-3309

    RansomwareCVE from 2016, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1198. Rank 1208Microsoft Windows

    CVE-2017-0101

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows Transaction Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1199. Rank 1209Microsoft Windows

    CVE-2019-0543

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1200. Rank 1210Microsoft Windows

    CVE-2019-0841

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1201. Rank 1211Microsoft Windows

    CVE-2019-1064

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1202. Rank 1212Microsoft Windows

    CVE-2019-1069

    RansomwareCVE from 2019, added in 2022

    Microsoft Task Scheduler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1203. Rank 1213Microsoft Windows

    CVE-2019-1129

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1204. Rank 1214Microsoft Windows

    CVE-2019-1132

    CVE from 2019, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1205. Rank 1215Microsoft Windows

    CVE-2019-1253

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1206. Rank 1216Microsoft Windows

    CVE-2019-1315

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1207. Rank 1217Microsoft Windows

    CVE-2019-1322

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1208. Rank 1218Microsoft Windows

    CVE-2019-1405

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1209. Rank 1219Microsoft Windows

    CVE-2002-0367

    CVE from 2002, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1210. Rank 1220Microsoft Windows

    CVE-2004-0210

    CVE from 2004, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1211. Rank 1221Adobe Acrobat / Reader

    CVE-2008-2992

    RansomwareCVE from 2008, added in 2022

    Adobe Reader and Acrobat Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1212. Rank 1222Microsoft Windows

    CVE-2009-1123

    CVE from 2009, added in 2022

    Microsoft Windows Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1213. Rank 1223Microsoft Office

    CVE-2009-3129

    CVE from 2009, added in 2022

    Microsoft Excel Featheader Record Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1214. Rank 1224Adobe Acrobat / Reader

    CVE-2010-0188

    RansomwareCVE from 2010, added in 2022

    Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1215. Rank 1225Microsoft Windows

    CVE-2010-0232

    CVE from 2010, added in 2022

    Microsoft Windows Kernel Exception Handler Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1216. Rank 1226Microsoft Office

    CVE-2010-3333

    CVE from 2010, added in 2022

    Microsoft Office Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1217. Rank 1227Adobe Acrobat / Reader

    CVE-2013-0640

    CVE from 2013, added in 2022

    Adobe Reader and Acrobat Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1218. Rank 1228Adobe Acrobat / Reader

    CVE-2013-0641

    CVE from 2013, added in 2022

    Adobe Reader Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1219. Rank 1229Microsoft Windows

    CVE-2013-5065

    CVE from 2013, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1220. Rank 1230Microsoft Windows

    CVE-2014-4114

    CVE from 2014, added in 2022

    Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1221. Rank 1231Microsoft Office

    CVE-2015-1642

    CVE from 2015, added in 2022

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1222. Rank 1232Microsoft Windows

    CVE-2015-1701

    RansomwareCVE from 2015, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1223. Rank 1233Microsoft Windows

    CVE-2015-2387

    CVE from 2015, added in 2022

    Microsoft ATM Font Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1224. Rank 1234Microsoft Office

    CVE-2015-2545

    CVE from 2015, added in 2022

    Microsoft Office Malformed EPS File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1225. Rank 1235Microsoft Windows

    CVE-2016-0099

    RansomwareCVE from 2016, added in 2022

    Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1226. Rank 1236Microsoft Office

    CVE-2016-7193

    CVE from 2016, added in 2022

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1227. Rank 1237Microsoft Office

    CVE-2016-7262

    CVE from 2016, added in 2022

    Microsoft Office Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1228. Rank 1238Microsoft Windows

    CVE-2017-0001

    CVE from 2017, added in 2022

    Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1229. Rank 1239Microsoft Office

    CVE-2017-0261

    CVE from 2017, added in 2022

    Microsoft Office Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1230. Rank 1240Microsoft Office

    CVE-2017-11826

    CVE from 2017, added in 2022

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1231. Rank 1241Microsoft Defender

    CVE-2017-8540

    CVE from 2017, added in 2022

    Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  1232. Rank 1242Microsoft Windows

    CVE-2021-41379

    Ransomware

    Microsoft Windows Installer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1233. Rank 1243Cisco RV routers (Small Business)

    CVE-2022-20701

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1234. Rank 1244Microsoft Windows

    CVE-2014-6352

    CVE from 2014, added in 2022

    Microsoft Windows Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1235. Rank 1245Microsoft Office

    CVE-2017-8570

    CVE from 2017, added in 2022

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1236. Rank 1246Microsoft Windows

    CVE-2013-3906

    CVE from 2013, added in 2022

    Microsoft Graphics Component Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1237. Rank 1247Microsoft Office

    CVE-2014-1761

    CVE from 2014, added in 2022

    Microsoft Word Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1238. Rank 1248RARLAB WinRAR

    CVE-2018-20250

    RansomwareCVE from 2018, added in 2022

    WinRAR Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1239. Rank 1249Apple macOS (OS X)

    CVE-2014-4404

    CVE from 2014, added in 2022

    Apple OS X Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1240. Rank 1250Apple macOS (OS X)

    CVE-2015-1130

    CVE from 2015, added in 2022

    Apple OS X Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1241. Rank 1251Microsoft Office

    CVE-2017-0262

    CVE from 2017, added in 2022

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1242. Rank 1252Microsoft Windows

    CVE-2017-0263

    CVE from 2017, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1243. Rank 1253Microsoft Windows

    CVE-2021-36934

    Microsoft Windows SAM Local Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1244. Rank 1254Microsoft Windows

    CVE-2022-21882

    Ransomware

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1245. Rank 1255Microsoft Windows

    CVE-2020-0787

    RansomwareCVE from 2020, added in 2022

    Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1246. Rank 1256Microsoft Windows

    CVE-2018-8453

    RansomwareCVE from 2018, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1247. Rank 1257systeminformation (npm) systeminformation

    CVE-2021-21315

    System Information Library for Node.JS Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1248. Rank 1258Microsoft Windows

    CVE-2019-1458

    RansomwareCVE from 2019, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1249. Rank 1259Linux Kernel

    CVE-2019-13272

    CVE from 2019, added in 2021

    Linux Kernel Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    7.8 (high)
  1250. Rank 1260Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2021-44168

    Fortinet FortiOS Arbitrary File Download

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1251. Rank 1261Qualcomm Snapdragon (chipsets and drivers)

    CVE-2020-11261

    Qualcomm Multiple Chipsets Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    182 days
    CVSS severity
    7.8 (high)
  1252. Rank 1262ExifTool

    CVE-2021-22204

    ExifTool Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1253. Rank 1263Microsoft Windows

    CVE-2021-40449

    Ransomware

    Microsoft Windows Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1254. Rank 1264Microsoft Office

    CVE-2021-42292

    Microsoft Excel Security Feature Bypass

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1255. Rank 1265Microsoft Office

    CVE-2015-1641

    CVE from 2015, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1256. Rank 1266Microsoft Windows

    CVE-2016-0167

    RansomwareCVE from 2016, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1257. Rank 1267Microsoft Windows

    CVE-2016-0185

    CVE from 2016, added in 2021

    Microsoft Windows Media Center Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1258. Rank 1268Microsoft Office

    CVE-2016-3235

    CVE from 2016, added in 2021

    Microsoft Office OLE DLL Side Loading Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1259. Rank 1269SolarWinds Virtualization Manager

    CVE-2016-3643

    CVE from 2016, added in 2021

    SolarWinds Virtualization Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1260. Rank 1270Microsoft Windows

    CVE-2016-7255

    RansomwareCVE from 2016, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1261. Rank 1271Microsoft Office

    CVE-2017-0199

    RansomwareCVE from 2017, added in 2021

    Microsoft Office and WordPad Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1262. Rank 1272Microsoft Office

    CVE-2017-11774

    CVE from 2017, added in 2021

    Microsoft Office Outlook Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1263. Rank 1273Microsoft Office

    CVE-2017-11882

    RansomwareCVE from 2017, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1264. Rank 1274Roundcube Webmail

    CVE-2017-16651

    CVE from 2017, added in 2021

    Roundcube Webmail File Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1265. Rank 1275Microsoft .NET / Visual Studio

    CVE-2017-8759

    CVE from 2017, added in 2021

    Microsoft .NET Framework Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1266. Rank 1276Microsoft Office

    CVE-2018-0802

    RansomwareCVE from 2018, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1267. Rank 1277Apache HTTP Server

    CVE-2019-0211

    CVE from 2019, added in 2021

    Apache HTTP Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1268. Rank 1278Microsoft Windows

    CVE-2019-0797

    CVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1269. Rank 1279Microsoft Windows

    CVE-2019-0803

    RansomwareCVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1270. Rank 1280Microsoft Windows

    CVE-2019-0808

    CVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1271. Rank 1281Microsoft Windows

    CVE-2019-0859

    RansomwareCVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1272. Rank 1282Microsoft Windows

    CVE-2019-0863

    CVE from 2019, added in 2021

    Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1273. Rank 1283Microsoft Windows

    CVE-2019-1214

    CVE from 2019, added in 2021

    Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1274. Rank 1284Microsoft Windows

    CVE-2019-1215

    RansomwareCVE from 2019, added in 2021

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1275. Rank 1285Docker Desktop

    CVE-2019-15752

    CVE from 2019, added in 2021

    Docker Desktop Community Edition Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1276. Rank 1286Google Android

    CVE-2019-2215

    CVE from 2019, added in 2021

    Android Kernel Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1277. Rank 1287Google Android

    CVE-2020-0041

    Android Kernel Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1278. Rank 1288MediaTek Chipsets

    CVE-2020-0069

    Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1279. Rank 1289Microsoft Windows

    CVE-2020-0683

    Microsoft Windows Installer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1280. Rank 1290Microsoft Windows

    CVE-2020-0938

    Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1281. Rank 1291Microsoft Windows

    CVE-2020-0986

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1282. Rank 1292Microsoft Windows

    CVE-2020-1054

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1283. Rank 1293Microsoft SharePoint Server

    CVE-2020-1147

    Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1284. Rank 1294Microsoft Windows

    CVE-2020-17087

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1285. Rank 1295Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-24557

    Trend Micro Multiple Products Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1286. Rank 1296Apple iOS / iPadOS / macOS

    CVE-2020-27930

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1287. Rank 1297Apple iOS / iPadOS / macOS

    CVE-2020-27932

    Apple Multiple Products Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1288. Rank 1298VMware (Broadcom) Workstation / Fusion

    CVE-2020-3950

    VMware Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1289. Rank 1299EyesOfNetwork

    CVE-2020-8655

    EyesOfNetwork Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1290. Rank 1300Apple iOS / iPadOS / macOS

    CVE-2020-9859

    Apple Multiple Products Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1291. Rank 1301Microsoft Defender

    CVE-2021-1647

    Microsoft Defender Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1292. Rank 1302Microsoft Windows

    CVE-2021-1675

    Ransomware

    Microsoft Windows Print Spooler Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1293. Rank 1303Microsoft Windows

    CVE-2021-1732

    Ransomware

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1294. Rank 1304Qualcomm Snapdragon (chipsets and drivers)

    CVE-2021-1905

    Qualcomm Multiple Chipsets Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1295. Rank 1305McAfee Total Protection (MTP)

    CVE-2021-23874

    McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1296. Rank 1306Microsoft Exchange Server

    CVE-2021-26857

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1297. Rank 1307Microsoft Exchange Server

    CVE-2021-26858

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1298. Rank 1308Microsoft Exchange Server

    CVE-2021-27065

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  1299. Rank 1309Kiteworks (Accellion) FTA (File Transfer Appliance)

    CVE-2021-27102

    Ransomware

    Accellion FTA OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1300. Rank 1310Microsoft Windows

    CVE-2021-28310

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1301. Rank 1311Apple macOS (OS X)

    CVE-2021-30713

    Apple macOS Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1302. Rank 1312Apple iOS / iPadOS / macOS

    CVE-2021-30807

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1303. Rank 1313Apple iOS / iPadOS / macOS

    CVE-2021-30860

    Apple Multiple Products Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1304. Rank 1314Apple iOS / iPadOS / macOS

    CVE-2021-30869

    Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1305. Rank 1315Microsoft Windows

    CVE-2021-31199

    Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1306. Rank 1316Microsoft Windows

    CVE-2021-31201

    Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1307. Rank 1317Microsoft Windows

    CVE-2021-31956

    Microsoft Windows NTFS Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1308. Rank 1318Microsoft Windows

    CVE-2021-31979

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1309. Rank 1319Microsoft Windows

    CVE-2021-33739

    Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1310. Rank 1320Microsoft Windows

    CVE-2021-33771

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1311. Rank 1321Trend Micro Apex One (ex-OfficeScan)

    CVE-2021-36742

    Trend Micro Multiple Products Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1312. Rank 1322Microsoft Windows

    CVE-2021-36948

    Microsoft Windows Update Medic Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1313. Rank 1323Microsoft Windows

    CVE-2021-36955

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1314. Rank 1324Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38645

    Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1315. Rank 1325Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38648

    Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1316. Rank 1326Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38649

    Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1317. Rank 1327Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-40444

    Ransomware

    Microsoft MSHTML Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  1318. Rank 1328Microsoft Windows

    CVE-2024-21351

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.6 (high)
  1319. Rank 1329D-Link DCS cameras

    CVE-2020-25078

    CVE from 2020, added in 2025

    D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1320. Rank 1330SysAid On-Prem

    CVE-2025-2775

    SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1321. Rank 1331Citrix NetScaler ADC / Gateway

    CVE-2025-5777

    Ransomware

    Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 10, 2025
    CISA deadline
    1 day
    CVSS severity
    7.5 (high)
  1322. Rank 1332Ruby on Rails

    CVE-2019-5418

    CVE from 2019, added in 2025

    Rails Ruby on Rails Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 7, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1323. Rank 1333Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2019-9621

    CVE from 2019, added in 2025

    Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 7, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1324. Rank 1334Qualcomm Snapdragon (chipsets and drivers)

    CVE-2025-27038

    Qualcomm Multiple Chipsets Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1325. Rank 1335ZKTeco BioTime

    CVE-2023-38950

    CVE from 2023, added in 2025

    ZKTeco BioTime Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1326. Rank 1336Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2025-4427

    Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1327. Rank 1337Microsoft Windows

    CVE-2025-30397

    Microsoft Windows Scripting Engine Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1328. Rank 1338SAP NetWeaver

    CVE-2017-12637

    CVE from 2017, added in 2025

    SAP NetWeaver Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 19, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1329. Rank 1339Ivanti Endpoint Manager (EPM)

    CVE-2024-13159

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1330. Rank 1340Ivanti Endpoint Manager (EPM)

    CVE-2024-13160

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1331. Rank 1341Ivanti Endpoint Manager (EPM)

    CVE-2024-13161

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1332. Rank 1342Advantive VeraCore

    CVE-2025-25181

    Advantive VeraCore SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1333. Rank 1343SimpleHelp

    CVE-2024-57727

    Ransomware

    SimpleHelp Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1334. Rank 1344Microsoft .NET / Visual Studio

    CVE-2024-29059

    Microsoft .NET Framework Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1335. Rank 1345Apache OFBiz

    CVE-2024-45195

    Apache OFBiz Forced Browsing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1336. Rank 1346Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-3393

    Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 30, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1337. Rank 1347North Grid Proself

    CVE-2023-45727

    North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1338. Rank 1348Oracle Agile PLM

    CVE-2024-21287

    Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1339. Rank 1349Palo Alto Networks Expedition

    CVE-2024-9463

    Palo Alto Networks Expedition OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1340. Rank 1350Metabase

    CVE-2021-41277

    CVE from 2021, added in 2024

    Metabase GeoJSON API Local File Inclusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1341. Rank 1351DrayTek VigorConnect

    CVE-2021-20123

    CVE from 2021, added in 2024

    Draytek VigorConnect Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1342. Rank 1352DrayTek VigorConnect

    CVE-2021-20124

    CVE from 2021, added in 2024

    Draytek VigorConnect Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1343. Rank 1353Microsoft Windows

    CVE-2024-38178

    Microsoft Windows Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1344. Rank 1354SolarWinds Serv-U

    CVE-2024-28995

    SolarWinds Serv-U Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1345. Rank 1355Microsoft Windows

    CVE-2024-38112

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1346. Rank 1356Apache Flink

    CVE-2020-17519

    CVE from 2020, added in 2024

    Apache Flink Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1347. Rank 1357Cisco ASA / Firepower (FTD)

    CVE-2020-3259

    RansomwareCVE from 2020, added in 2024

    Cisco ASA and FTD Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1348. Rank 1358Citrix NetScaler ADC / Gateway

    CVE-2023-6549

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1349. Rank 1359ownCloud Server

    CVE-2023-49103

    ownCloud graphapi Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 30, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1350. Rank 1360Protocoles (IETF) Service Location Protocol (SLP)

    CVE-2023-29552

    Service Location Protocol (SLP) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1351. Rank 1361Citrix NetScaler ADC / Gateway

    CVE-2023-4966

    Ransomware

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 18, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1352. Rank 1362Protocoles (IETF) HTTP/2

    CVE-2023-44487

    HTTP/2 Rapid Reset Attack Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1353. Rank 1363Ignite Realtime Openfire

    CVE-2023-32315

    Ignite Realtime Openfire Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 24, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1354. Rank 1364Veeam Backup & Replication

    CVE-2023-27532

    Ransomware

    Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 22, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1355. Rank 1365Microsoft .NET / Visual Studio

    CVE-2023-38180

    Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 9, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1356. Rank 1366Adobe ColdFusion

    CVE-2023-29298

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1357. Rank 1367Adobe ColdFusion

    CVE-2023-38205

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1358. Rank 1368Microsoft Windows

    CVE-2023-36884

    Ransomware

    Microsoft Windows Search Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2023
    CISA deadline
    43 days
    CVSS severity
    7.5 (high)
  1359. Rank 1369Microsoft Outlook

    CVE-2023-35311

    Microsoft Outlook Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1360. Rank 1370Mozilla Firefox

    CVE-2016-9079

    CVE from 2016, added in 2023

    Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1361. Rank 1371Cisco IOS / IOS XE / IOS XR

    CVE-2016-6415

    CVE from 2016, added in 2023

    Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1362. Rank 1372Jenkins Core

    CVE-2015-5317

    CVE from 2015, added in 2023

    Jenkins User Interface (UI) Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1363. Rank 1373Oracle WebLogic Server

    CVE-2023-21839

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1364. Rank 1374MinIO

    CVE-2023-28432

    MinIO Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 21, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1365. Rank 1375ZK Framework AuUploader

    CVE-2022-36537

    Ransomware

    ZK Framework AuUploader Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 27, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1366. Rank 1376TerraMaster OS

    CVE-2022-24990

    Ransomware

    TerraMaster OS Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1367. Rank 1377PEAR Archive_Tar

    CVE-2020-36193

    CVE from 2020, added in 2022

    PEAR Archive_Tar Improper Link Resolution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1368. Rank 1378Apple iOS / iPadOS / macOS

    CVE-2021-31010

    Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1369. Rank 1379RARLAB UnRAR

    CVE-2022-30333

    Ransomware

    RARLAB UnRAR Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 9, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1370. Rank 1380Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-27924

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 4, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1371. Rank 1381Red Hat JBoss Application Server / EAP

    CVE-2010-1428

    RansomwareCVE from 2010, added in 2022

    Red Hat JBoss Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1372. Rank 1382Microsoft Windows

    CVE-2017-0147

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows SMBv1 Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1373. Rank 1383OpenSSL

    CVE-2014-0160

    CVE from 2014, added in 2022

    OpenSSL Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1374. Rank 1384Trihedral VTScada (formerly VTS)

    CVE-2016-4523

    CVE from 2016, added in 2022

    Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1375. Rank 1385Microsoft Active Directory

    CVE-2021-42278

    Ransomware

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1376. Rank 1386Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-0189

    RansomwareCVE from 2016, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1377. Rank 1387SonicWall SMA 100 (ex-SRA)

    CVE-2019-7483

    CVE from 2019, added in 2022

    SonicWall SMA100 Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1378. Rank 1388Cisco IOS XR

    CVE-2010-3035

    CVE from 2010, added in 2022

    Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1379. Rank 1389Ruby on Rails

    CVE-2014-0130

    CVE from 2014, added in 2022

    Ruby on Rails Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1380. Rank 1390Cisco Prime Data Center Network Manager (DCNM)

    CVE-2015-0666

    CVE from 2015, added in 2022

    Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1381. Rank 1391TP-Link Archer (Wi-Fi routers)

    CVE-2015-3035

    CVE from 2015, added in 2022

    TP-Link Multiple Archer Devices Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1382. Rank 1392Ruby on Rails

    CVE-2016-0752

    CVE from 2016, added in 2022

    Ruby on Rails Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1383. Rank 1393Microsoft Internet Explorer / Edge (legacy)

    CVE-2018-8373

    CVE from 2018, added in 2022

    Microsoft Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1384. Rank 1394Spring Cloud Config

    CVE-2020-5410

    CVE from 2020, added in 2022

    VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1385. Rank 1395Adobe ColdFusion

    CVE-2013-0629

    CVE from 2013, added in 2022

    Adobe ColdFusion Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.5 (high)
  1386. Rank 1396Adobe ColdFusion

    CVE-2013-0631

    CVE from 2013, added in 2022

    Adobe ColdFusion Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.5 (high)
  1387. Rank 1397Siemens SIMATIC CP

    CVE-2016-8562

    CVE from 2016, added in 2022

    Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1388. Rank 1398Cisco IOS / IOS XE

    CVE-2017-12231

    CVE from 2017, added in 2022

    Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1389. Rank 1399Cisco IOS / IOS XE

    CVE-2017-12233

    CVE from 2017, added in 2022

    Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1390. Rank 1400Cisco IOS / IOS XE

    CVE-2017-12234

    CVE from 2017, added in 2022

    Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1391. Rank 1401Cisco IOS / IOS XE

    CVE-2017-12235

    CVE from 2017, added in 2022

    Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1392. Rank 1402Cisco IOS / IOS XE

    CVE-2017-12237

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1393. Rank 1403Cisco IOS / IOS XE

    CVE-2017-6627

    CVE from 2017, added in 2022

    Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  1394. Rank 1404Cisco IOS / IOS XE

    CVE-2018-0154

    CVE from 2018, added in 2022

    Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1395. Rank 1405Cisco IOS / IOS XE

    CVE-2018-0156

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1396. Rank 1406Cisco IOS / IOS XE

    CVE-2018-0159

    CVE from 2018, added in 2022

    Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1397. Rank 1407ChakraCore scripting engine

    CVE-2018-8298

    CVE from 2018, added in 2022

    ChakraCore Scripting Engine Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1398. Rank 1408Microsoft Windows

    CVE-2018-8174

    RansomwareCVE from 2018, added in 2022

    Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1399. Rank 1409Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0752

    RansomwareCVE from 2019, added in 2022

    Microsoft Internet Explorer Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1400. Rank 1410Oracle WebLogic Server

    CVE-2017-10271

    RansomwareCVE from 2017, added in 2022

    Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1401. Rank 1411Apache Struts 1

    CVE-2006-1547

    CVE from 2006, added in 2022

    Apache Struts 1 ActionForm Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1402. Rank 1412Oracle Business Intelligence (OBIEE / BI Publisher)

    CVE-2020-14864

    CVE from 2020, added in 2022

    Oracle Business Intelligence Enterprise Edition Path Transversal

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1403. Rank 1413VMware (Broadcom) Aria Operations (ex-vRealize Operations)

    CVE-2021-21975

    Ransomware

    VMware Server Side Request Forgery in vRealize Operations Manager API

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1404. Rank 1414Microsoft Exchange Server

    CVE-2021-33766

    Microsoft Exchange Server Information Disclosure

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1405. Rank 1415Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13382

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiProxy Improper Authorization

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1406. Rank 1416SAP NetWeaver

    CVE-2016-3976

    CVE from 2016, added in 2021

    SAP NetWeaver Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1407. Rank 1417Cisco ASA / Firepower (FTD)

    CVE-2018-0296

    CVE from 2018, added in 2021

    Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1408. Rank 1418DotNetNuke (DNN)

    CVE-2018-15811

    CVE from 2018, added in 2021

    DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1409. Rank 1419DotNetNuke (DNN)

    CVE-2018-18325

    CVE from 2018, added in 2021

    DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1410. Rank 1420Microsoft Internet Explorer / Edge (legacy)

    CVE-2018-8653

    CVE from 2018, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1411. Rank 1421Citrix StoreFront

    CVE-2019-13608

    RansomwareCVE from 2019, added in 2021

    Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1412. Rank 1422Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-1367

    RansomwareCVE from 2019, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1413. Rank 1423Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-1429

    CVE from 2019, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1414. Rank 1424Cisco RV routers (Small Business)

    CVE-2019-1653

    CVE from 2019, added in 2021

    Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1415. Rank 1425Apache Solr

    CVE-2019-17558

    CVE from 2019, added in 2021

    Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1416. Rank 1426Trend Micro Apex One (ex-OfficeScan)

    CVE-2019-18187

    CVE from 2019, added in 2021

    Trend Micro OfficeScan Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1417. Rank 1427Netis WF2419 Devices

    CVE-2019-19356

    CVE from 2019, added in 2021

    Netis WF2419 Devices Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1418. Rank 1428TVT NVMS-1000

    CVE-2019-20085

    CVE from 2019, added in 2021

    TVT NVMS-1000 Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1419. Rank 1429Apple iOS / iPadOS / macOS

    CVE-2019-6223

    CVE from 2019, added in 2021

    Apple iOS and macOS Group Facetime Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1420. Rank 1430SonicWall SMA 100 (ex-SRA)

    CVE-2019-7481

    RansomwareCVE from 2019, added in 2021

    SonicWall SMA100 SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1421. Rank 1431Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0674

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1422. Rank 1432Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0878

    Ransomware

    Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1423. Rank 1433Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0968

    Ransomware

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1424. Rank 1434WordPress Plugins

    CVE-2020-11738

    WordPress Snap Creek Duplicator Plugin File Download Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1425. Rank 1435Cisco ASA / Firepower (FTD)

    CVE-2020-3452

    Cisco ASA and FTD Read-Only Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1426. Rank 1436Unraid

    CVE-2020-5849

    Unraid Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  1427. Rank 1437OpenText (Micro Focus) Access Manager (NetIQ)

    CVE-2021-22506

    Micro Focus Access Manager Information Leakage Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1428. Rank 1438Microsoft Windows

    CVE-2021-36942

    Ransomware

    Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  1429. Rank 1439Adobe ColdFusion

    CVE-2024-20767

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.4 (high)
  1430. Rank 1440Oracle WebLogic Server

    CVE-2017-3506

    CVE from 2017, added in 2024

    Oracle WebLogic Server OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.4 (high)
  1431. Rank 1441Microsoft Exchange Server

    CVE-2018-8581

    RansomwareCVE from 2018, added in 2022

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.4 (high)
  1432. Rank 1442Google Android

    CVE-2024-43093

    Android Framework Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2024
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  1433. Rank 1443Microsoft Office

    CVE-2024-38226

    Microsoft Publisher Protection Mechanism Failure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 10, 2024
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  1434. Rank 1444Microsoft Office

    CVE-2023-21715

    Microsoft Office Publisher Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  1435. Rank 1445Grafana Labs Grafana

    CVE-2021-39226

    Grafana Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  1436. Rank 1446Adobe Acrobat / Reader

    CVE-2010-2883

    CVE from 2010, added in 2022

    Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.3 (high)
  1437. Rank 1447Microsoft Windows

    CVE-2017-0213

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  1438. Rank 1448TP-Link Archer (Wi-Fi routers)

    CVE-2025-9377

    TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1439. Rank 1449ConnectWise ScreenConnect

    CVE-2025-3935

    ConnectWise ScreenConnect Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1440. Rank 1450SonicWall SMA 100 (ex-SRA)

    CVE-2023-44221

    CVE from 2023, added in 2025

    SonicWall SMA100 Appliances OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1441. Rank 1451Hitachi Vantara Pentaho Business Analytics (BA) Server

    CVE-2022-43769

    CVE from 2022, added in 2025

    Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1442. Rank 1452Cisco RV routers (Small Business)

    CVE-2023-20118

    CVE from 2023, added in 2025

    Cisco Small Business RV Series Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1443. Rank 1453Mitel SIP Phones (6800 / 6900)

    CVE-2024-41710

    Mitel SIP Phones Argument Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 12, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1444. Rank 1454Paessler PRTG Network Monitor

    CVE-2018-9276

    CVE from 2018, added in 2025

    Paessler PRTG Network Monitor OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1445. Rank 1455BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2024-12686

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1446. Rank 1456Reolink IP cameras

    CVE-2019-11001

    CVE from 2019, added in 2024

    Reolink Multiple IP Cameras OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1447. Rank 1457Reolink IP cameras

    CVE-2021-40407

    CVE from 2021, added in 2024

    Reolink RLC-410W IP Camera OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1448. Rank 1458Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-9474

    Ransomware

    Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 18, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1449. Rank 1459PTZOptics PT30X-SDI/NDI Cameras

    CVE-2024-8957

    PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 4, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1450. Rank 1460Microsoft SharePoint Server

    CVE-2024-38094

    Ransomware

    Microsoft SharePoint Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 22, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1451. Rank 1461Versa Networks Director

    CVE-2024-39717

    Versa Director Dangerous File Type Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 23, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1452. Rank 1462Microsoft Exchange Server

    CVE-2021-31196

    CVE from 2021, added in 2024

    Microsoft Exchange Server Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1453. Rank 1463VMware (Broadcom) ESXi

    CVE-2024-37085

    Ransomware

    VMware ESXi Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 30, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1454. Rank 1464Microsoft SharePoint Server

    CVE-2023-24955

    Ransomware

    Microsoft SharePoint Server Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 26, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1455. Rank 1465Cisco IOS / IOS XE

    CVE-2023-20273

    Cisco IOS XE Web UI Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 23, 2023
    CISA deadline
    4 days
    CVSS severity
    7.2 (high)
  1456. Rank 1466Trend Micro Apex One (ex-OfficeScan)

    CVE-2023-41179

    Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 21, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1457. Rank 1467Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35081

    Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 31, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1458. Rank 1468Plex Media Server

    CVE-2020-5741

    CVE from 2020, added in 2023

    Plex Media Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1459. Rank 1469Fortra GoAnywhere MFT

    CVE-2023-0669

    Ransomware

    Fortra GoAnywhere MFT Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1460. Rank 1470Trend Micro Apex One (ex-OfficeScan)

    CVE-2022-40139

    Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1461. Rank 1471Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-27925

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1462. Rank 1472Oracle Business Intelligence (OBIEE / BI Publisher)

    CVE-2019-2616

    CVE from 2019, added in 2022

    Oracle BI Publisher Unauthorized Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  1463. Rank 1473Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8218

    CVE from 2020, added in 2022

    Pulse Connect Secure Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.2 (high)
  1464. Rank 1474Cisco RV routers (Small Business)

    CVE-2019-1652

    CVE from 2019, added in 2022

    Cisco Small Business Routers Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  1465. Rank 1475Apache Solr

    CVE-2019-0193

    CVE from 2019, added in 2021

    Apache Solr DataImportHandler Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    7.2 (high)
  1466. Rank 1476Pi-hole AdminLTE

    CVE-2020-8816

    Pi-Hole AdminLTE Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    7.2 (high)
  1467. Rank 1477Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2019-11539

    RansomwareCVE from 2019, added in 2021

    Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  1468. Rank 1478Oracle WebLogic Server

    CVE-2020-14883

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  1469. Rank 1479Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8243

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  1470. Rank 1480Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8260

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  1471. Rank 1481SonicWall Email Security

    CVE-2021-20022

    Ransomware

    SonicWall Email Security Unrestricted Upload of File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  1472. Rank 1482Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22900

    Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  1473. Rank 1483Linux Kernel

    CVE-2024-53150

    Linux Kernel Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 9, 2025
    CISA deadline
    21 days
    CVSS severity
    7.1 (high)
  1474. Rank 1484Microsoft Windows

    CVE-2025-21391

    Microsoft Windows Storage Link Following Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.1 (high)
  1475. Rank 1485Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-41328

    Fortinet FortiOS Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.1 (high)
  1476. Rank 1486Samsung Mobile Devices (Galaxy)

    CVE-2021-25337

    Samsung Mobile Devices Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    21 days
    CVSS severity
    7.1 (high)
  1477. Rank 1487Microsoft Windows

    CVE-2021-43890

    Ransomware

    Microsoft Windows AppX Installer Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 15, 2021
    CISA deadline
    14 days
    CVSS severity
    7.1 (high)
  1478. Rank 1488Microsoft Windows

    CVE-2025-24983

    Microsoft Windows Win32k Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1479. Rank 1489Microsoft Windows

    CVE-2025-26633

    Ransomware

    Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1480. Rank 14907-Zip

    CVE-2025-0411

    7-Zip Mark of the Web Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1481. Rank 1491Microsoft Windows

    CVE-2024-30088

    Ransomware

    Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 15, 2024
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1482. Rank 1492Microsoft Windows

    CVE-2024-38106

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1483. Rank 1493Apple iOS / iPadOS / macOS

    CVE-2022-48618

    CVE from 2022, added in 2024

    Apple Multiple Products Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 31, 2024
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1484. Rank 1494Microsoft Windows

    CVE-2023-28229

    Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 4, 2023
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1485. Rank 1495Linux Kernel

    CVE-2023-0266

    Linux Kernel Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1486. Rank 1496Microsoft Windows

    CVE-2022-21919

    Microsoft Windows User Profile Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1487. Rank 1497Microsoft Windows

    CVE-2022-26904

    Microsoft Windows User Profile Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1488. Rank 1498Linux Kernel

    CVE-2021-22600

    Linux Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1489. Rank 1499Microsoft Windows

    CVE-2018-8120

    RansomwareCVE from 2018, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1490. Rank 1500Linux Kernel

    CVE-2016-5195

    CVE from 2016, added in 2022

    Linux Kernel Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  1491. Rank 1501TeamViewer Desktop

    CVE-2019-18988

    CVE from 2019, added in 2021

    TeamViewer Desktop Bypass Remote Login Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.0 (high)
  1492. Rank 1502Apple iOS / iPadOS / macOS

    CVE-2021-1782

    Apple Multiple Products Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.0 (high)
  1493. Rank 1503ManageEngine (Zoho) ADSelfService Plus

    CVE-2022-28810

    Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  1494. Rank 1504Mitel MiVoice Connect

    CVE-2022-40765

    Ransomware

    Mitel MiVoice Connect Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  1495. Rank 1505Mitel MiVoice Connect

    CVE-2022-41223

    Ransomware

    Mitel MiVoice Connect Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  1496. Rank 1506Brocade Fabric OS (FOS)

    CVE-2025-1976

    Broadcom Brocade Fabric OS Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 28, 2025
    CISA deadline
    21 days
    CVSS severity
    6.7 (medium)
  1497. Rank 1507Cisco NX-OS

    CVE-2024-20399

    Cisco NX-OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 2, 2024
    CISA deadline
    21 days
    CVSS severity
    6.7 (medium)
  1498. Rank 1508Samsung Mobile Devices (Galaxy)

    CVE-2021-25371

    CVE from 2021, added in 2023

    Samsung Mobile Devices Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    6.7 (medium)
  1499. Rank 1509Samsung Mobile Devices (Galaxy)

    CVE-2021-25372

    CVE from 2021, added in 2023

    Samsung Mobile Devices Improper Boundary Check Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    6.7 (medium)
  1500. Rank 1510Cisco IOS / IOS XE

    CVE-2023-20109

    Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    6.6 (medium)
  1501. Rank 1511Microsoft Windows

    CVE-2015-1769

    CVE from 2015, added in 2022

    Microsoft Windows Mount Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.6 (medium)
  1502. Rank 1512SAP CRM

    CVE-2018-2380

    RansomwareCVE from 2018, added in 2021

    SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.6 (medium)
  1503. Rank 1513Microsoft Exchange Server

    CVE-2021-31207

    Ransomware

    Microsoft Exchange Server Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.6 (medium)
  1504. Rank 1514TP-Link TL-WR (Wi-Fi routers)

    CVE-2023-50224

    CVE from 2023, added in 2025

    TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1505. Rank 1515Microsoft SharePoint Server

    CVE-2025-49706

    Ransomware

    Microsoft SharePoint Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    1 day
    CVSS severity
    6.5 (medium)
  1506. Rank 1516Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2019-6693

    RansomwareCVE from 2019, added in 2025

    Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1507. Rank 1517SonicWall SMA 100 (ex-SRA)

    CVE-2021-20035

    CVE from 2021, added in 2025

    SonicWall SMA100 Appliances OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 16, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1508. Rank 1518Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2025-0111

    Palo Alto Networks PAN-OS File Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 20, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1509. Rank 1519Microsoft Windows

    CVE-2024-43451

    Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1510. Rank 1520Microsoft Windows

    CVE-2024-38213

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1511. Rank 1521VMware (Broadcom) vCenter Server

    CVE-2022-22948

    CVE from 2022, added in 2024

    VMware vCenter Server Incorrect Default File Permissions Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1512. Rank 1522Qlik Sense

    CVE-2023-41266

    Ransomware

    Qlik Sense Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 7, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1513. Rank 1523Apple Safari / WebKit

    CVE-2023-42916

    Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 4, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1514. Rank 1524Microsoft Office

    CVE-2023-36761

    Microsoft Word Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 12, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1515. Rank 1525Apple Safari / WebKit

    CVE-2023-28204

    Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1516. Rank 1526TIBCO JasperReports

    CVE-2018-18809

    CVE from 2018, added in 2022

    TIBCO JasperReports Library Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 29, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1517. Rank 1527Cisco AnyConnect Secure Mobility Client

    CVE-2020-3153

    RansomwareCVE from 2020, added in 2022

    Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1518. Rank 1528Google Chrome / Chromium

    CVE-2022-2856

    Google Chromium Intents Insufficient Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1519. Rank 1529Google Chrome / Chromium

    CVE-2021-30533

    Google Chromium PopupBlocker Security Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1520. Rank 1530Google Chrome / Chromium

    CVE-2019-5825

    CVE from 2019, added in 2022

    Google Chromium V8 Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  1521. Rank 1531Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-7331

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1522. Rank 1532Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-0071

    CVE from 2015, added in 2022

    Microsoft Internet Explorer ASLR Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1523. Rank 1533Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-3298

    CVE from 2016, added in 2022

    Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1524. Rank 1534Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-3351

    RansomwareCVE from 2016, added in 2022

    Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1525. Rank 1535Microsoft Windows

    CVE-2017-0022

    CVE from 2017, added in 2022

    Microsoft XML Core Services Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1526. Rank 1536Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0676

    CVE from 2019, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1527. Rank 1537Microsoft Windows

    CVE-2019-0703

    CVE from 2019, added in 2022

    Microsoft Windows SMB Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1528. Rank 1538Google Chrome / Chromium

    CVE-2019-5786

    CVE from 2019, added in 2022

    Google Chrome Blink Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1529. Rank 1539Cisco IOS XR

    CVE-2022-20821

    Cisco IOS XR Open Port Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1530. Rank 1540Adobe BlazeDS

    CVE-2009-3960

    RansomwareCVE from 2009, added in 2022

    Adobe BlazeDS Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    6.5 (medium)
  1531. Rank 1541Mozilla Firefox

    CVE-2013-1675

    CVE from 2013, added in 2022

    Mozilla Firefox Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1532. Rank 1542Cisco IOS / IOS XE

    CVE-2017-12232

    CVE from 2017, added in 2022

    Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1533. Rank 1543Cisco IOS / IOS XE

    CVE-2017-12238

    CVE from 2017, added in 2022

    Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1534. Rank 1544Cisco IOS / IOS XE

    CVE-2017-6663

    CVE from 2017, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  1535. Rank 1545Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13383

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiProxy Out-of-bounds Write

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  1536. Rank 1546SAP NetWeaver

    CVE-2016-9563

    CVE from 2016, added in 2021

    SAP NetWeaver XML External Entity (XXE) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  1537. Rank 1547Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2019-5591

    RansomwareCVE from 2019, added in 2021

    Fortinet FortiOS Default Configuration Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  1538. Rank 1548ManageEngine (Zoho) ServiceDesk Plus

    CVE-2019-8394

    CVE from 2019, added in 2021

    Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  1539. Rank 1549SaltStack Salt

    CVE-2020-11652

    SaltStack Salt Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  1540. Rank 1550Citrix NetScaler ADC / Gateway

    CVE-2020-8193

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  1541. Rank 1551Citrix NetScaler ADC / Gateway

    CVE-2020-8195

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  1542. Rank 1552Microsoft Office

    CVE-2021-27059

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  1543. Rank 1553Google Chrome / Chromium

    CVE-2021-37976

    Google Chromium Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  1544. Rank 1554Samsung Mobile Devices (Galaxy)

    CVE-2021-25394

    CVE from 2021, added in 2023

    Samsung Mobile Devices Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    6.4 (medium)
  1545. Rank 1555Samsung Mobile Devices (Galaxy)

    CVE-2021-25395

    CVE from 2021, added in 2023

    Samsung Mobile Devices Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    6.4 (medium)
  1546. Rank 1556Google Android

    CVE-2021-0920

    Android Kernel Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.4 (medium)
  1547. Rank 1557Apple Safari / WebKit

    CVE-2024-44309

    Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2024
    CISA deadline
    21 days
    CVSS severity
    6.3 (medium)
  1548. Rank 1558Cisco IOS / IOS XE

    CVE-2018-0161

    CVE from 2018, added in 2022

    Cisco IOS Software Resource Management Errors Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    6.3 (medium)
  1549. Rank 1559MDaemon Email Server

    CVE-2024-11182

    MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1550. Rank 1560Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2024-27443

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1551. Rank 1561Apple iOS / iPadOS

    CVE-2025-24200

    Apple iOS and iPadOS Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 12, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1552. Rank 1562jQuery

    CVE-2020-11023

    CVE from 2020, added in 2025

    JQuery Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 23, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1553. Rank 1563Cisco ASA / Firepower (FTD)

    CVE-2014-2120

    CVE from 2014, added in 2024

    Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1554. Rank 1564Roundcube Webmail

    CVE-2024-37383

    RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1555. Rank 1565Roundcube Webmail

    CVE-2020-13965

    CVE from 2020, added in 2024

    Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 26, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1556. Rank 1566Roundcube Webmail

    CVE-2023-43770

    Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1557. Rank 1567Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2023-37580

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 27, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1558. Rank 1568Roundcube Webmail

    CVE-2020-35730

    CVE from 2020, added in 2023

    Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1559. Rank 1569Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-27926

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 3, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1560. Rank 1570Fortra Cobalt Strike

    CVE-2022-39197

    Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1561. Rank 1571QNAP NAS (QTS / QuTS hero)

    CVE-2018-19953

    RansomwareCVE from 2018, added in 2022

    QNAP NAS File Station Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1562. Rank 1572Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2018-6882

    RansomwareCVE from 2018, added in 2022

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2022
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  1563. Rank 1573Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-24682

    Ransomware

    Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  1564. Rank 1574WordPress Plugins

    CVE-2019-9978

    CVE from 2019, added in 2021

    WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.1 (medium)
  1565. Rank 1575Cisco ASA / Firepower (FTD)

    CVE-2020-3580

    Ransomware

    Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.1 (medium)
  1566. Rank 1576Apple Safari / WebKit

    CVE-2021-1879

    Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  1567. Rank 1577Google Chrome / Chromium

    CVE-2021-38000

    Google Chromium Intents Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  1568. Rank 1578VMware (Broadcom) ESXi

    CVE-2025-22226

    VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2025
    CISA deadline
    21 days
    CVSS severity
    6.0 (medium)
  1569. Rank 1579Cisco ASA / Firepower (FTD)

    CVE-2024-20359

    Cisco ASA and FTD Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    6.0 (medium)
  1570. Rank 1580Cisco IOS / IOS XE

    CVE-2004-1464

    CVE from 2004, added in 2023

    Cisco IOS Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2023
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  1571. Rank 1581Microsoft Windows

    CVE-2022-26925

    Microsoft Windows LSA Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 1, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  1572. Rank 1582Cisco IOS XR

    CVE-2009-2055

    CVE from 2009, added in 2022

    Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  1573. Rank 1583Cisco IOS / IOS XE

    CVE-2017-12319

    CVE from 2017, added in 2022

    Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  1574. Rank 1584Cisco IOS / IOS XE

    CVE-2018-0179

    CVE from 2018, added in 2022

    Cisco IOS Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  1575. Rank 1585Cisco IOS / IOS XE

    CVE-2018-0180

    CVE from 2018, added in 2022

    Cisco IOS Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  1576. Rank 1586Cisco ASA / Firepower (FTD)

    CVE-2024-20481

    Cisco ASA and FTD Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2024
    CISA deadline
    21 days
    CVSS severity
    5.8 (medium)
  1577. Rank 1587Microsoft Windows

    CVE-2025-24991

    Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1578. Rank 1588Linux Kernel

    CVE-2024-50302

    Linux Kernel Use of Uninitialized Resource Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2025
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1579. Rank 1589Google Pixel

    CVE-2024-29745

    Android Pixel Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2024
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1580. Rank 1590Google Pixel

    CVE-2023-21237

    Android Pixel Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 5, 2024
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1581. Rank 1591Microsoft WordPad

    CVE-2023-36563

    Microsoft WordPad Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1582. Rank 1592Arm Mali GPU (pilote noyau)

    CVE-2023-4211

    Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 3, 2023
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1583. Rank 1593Apple iOS / iPadOS / macOS

    CVE-2023-41991

    Apple Multiple Products Improper Certificate Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2023
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1584. Rank 1594Apple iOS / iPadOS / macOS

    CVE-2023-38606

    Apple Multiple Products Kernel Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 26, 2023
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1585. Rank 1595Samsung Mobile Devices (Galaxy)

    CVE-2021-25489

    CVE from 2021, added in 2023

    Samsung Mobile Devices Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1586. Rank 1596Samsung Mobile Devices (Galaxy)

    CVE-2021-25369

    Samsung Mobile Devices Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1587. Rank 1597Apple iOS / iPadOS / macOS

    CVE-2020-9934

    CVE from 2020, added in 2022

    Apple iOS, iPadOS, and macOS Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1588. Rank 1598Apple iOS / iPadOS

    CVE-2016-4655

    CVE from 2016, added in 2022

    Apple iOS Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1589. Rank 1599Apple macOS (OS X)

    CVE-2022-22674

    Apple macOS Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2022
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  1590. Rank 1600ImageMagick

    CVE-2016-3715

    CVE from 2016, added in 2021

    ImageMagick Arbitrary File Deletion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    5.5 (medium)
  1591. Rank 1601ImageMagick

    CVE-2016-3718

    CVE from 2016, added in 2021

    ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    5.5 (medium)
  1592. Rank 1602Microsoft Windows

    CVE-2020-1464

    Microsoft Windows Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    5.5 (medium)
  1593. Rank 1603Apple iOS / iPadOS / macOS

    CVE-2020-27950

    Apple Multiple Products Memory Initialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    5.5 (medium)
  1594. Rank 1604Qualcomm Snapdragon (chipsets and drivers)

    CVE-2021-1906

    Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    5.5 (medium)
  1595. Rank 1605Arm Trusted Firmware

    CVE-2021-27562

    Arm Trusted Firmware Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    5.5 (medium)
  1596. Rank 1606Apple macOS (OS X)

    CVE-2021-30657

    Apple macOS Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    5.5 (medium)
  1597. Rank 1607Microsoft Windows

    CVE-2021-31955

    Microsoft Windows Kernel Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    5.5 (medium)
  1598. Rank 1608Meta WhatsApp

    CVE-2025-55177

    Meta Platforms WhatsApp Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 2, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1599. Rank 1609Microsoft Windows

    CVE-2025-24054

    Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1600. Rank 1610Microsoft Windows

    CVE-2024-38217

    Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 10, 2024
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1601. Rank 1611Microsoft Windows

    CVE-2023-36584

    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 16, 2023
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1602. Rank 1612Roundcube Webmail

    CVE-2023-5631

    Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 26, 2023
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1603. Rank 1613Microsoft Defender

    CVE-2022-44698

    Ransomware

    Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1604. Rank 1614Microsoft Windows

    CVE-2022-41049

    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2022
    CISA deadline
    25 days
    CVSS severity
    5.4 (medium)
  1605. Rank 1615Microsoft Windows

    CVE-2022-41091

    Ransomware

    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    5.4 (medium)
  1606. Rank 1616QNAP NAS (QTS / QuTS hero)

    CVE-2018-19943

    RansomwareCVE from 2018, added in 2022

    QNAP NAS File Station Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1607. Rank 1617D-Link DSL modem-routers

    CVE-2013-5223

    CVE from 2013, added in 2022

    D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  1608. Rank 1618Treck Pile TCP/IP

    CVE-2020-11899

    CVE from 2020, added in 2022

    Treck TCP/IP stack Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    5.4 (medium)
  1609. Rank 1619TeleMessage TM SGNL

    CVE-2025-48927

    TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 1, 2025
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1610. Rank 1620Craft CMS

    CVE-2025-35939

    Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1611. Rank 1621Atlassian Jira Server / Data Center

    CVE-2021-26086

    CVE from 2021, added in 2024

    Atlassian Jira Server and Data Center Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1612. Rank 1622Twilio Authy

    CVE-2024-39891

    Twilio Authy Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 23, 2024
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1613. Rank 1623Joomla!

    CVE-2023-23752

    Joomla! Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1614. Rank 1624Juniper Junos OS

    CVE-2023-36844

    Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  1615. Rank 1625Juniper Junos OS

    CVE-2023-36846

    Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  1616. Rank 1626Juniper Junos OS

    CVE-2023-36847

    Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  1617. Rank 1627Juniper Junos OS

    CVE-2023-36851

    Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  1618. Rank 1628Microsoft Skype for Business / Lync

    CVE-2023-41763

    Microsoft Skype for Business Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1619. Rank 1629SAP NetWeaver

    CVE-2016-2388

    CVE from 2016, added in 2022

    SAP NetWeaver Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1620. Rank 1630Red Hat JBoss Application Server / EAP

    CVE-2010-0738

    RansomwareCVE from 2010, added in 2022

    Red Hat JBoss Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1621. Rank 1631Oracle Java SE (JRE / JDK)

    CVE-2013-0431

    RansomwareCVE from 2013, added in 2022

    Oracle JRE Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1622. Rank 1632Atlassian Confluence Server / Data Center

    CVE-2021-26085

    Ransomware

    Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1623. Rank 1633VMware (Broadcom) vCenter Server

    CVE-2021-21973

    VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  1624. Rank 1634Oracle Java SE (JRE / JDK)

    CVE-2015-4902

    CVE from 2015, added in 2022

    Oracle Java SE Integrity Check Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  1625. Rank 1635Zabbix Frontend

    CVE-2022-23134

    Zabbix Frontend Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 22, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  1626. Rank 1636SolarWinds Serv-U

    CVE-2021-35247

    SolarWinds Serv-U Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  1627. Rank 1637VMware (Broadcom) vCenter Server

    CVE-2021-22017

    VMware vCenter Server Improper Access Control

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  1628. Rank 1638TeleMessage TM SGNL

    CVE-2025-47729

    TeleMessage TM SGNL Hidden Functionality Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2025
    CISA deadline
    21 days
    CVSS severity
    4.9 (medium)
  1629. Rank 1639SonicWall Email Security

    CVE-2021-20023

    Ransomware

    SonicWall Email Security Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    4.9 (medium)
  1630. Rank 1640Oracle Identity and Access Management (OIM / OAM)

    CVE-2012-0518

    CVE from 2012, added in 2022

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    4.7 (medium)
  1631. Rank 1641Microsoft Windows

    CVE-2025-24984

    Microsoft Windows NTFS Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    4.6 (medium)
  1632. Rank 1642Juniper Junos OS

    CVE-2025-21590

    Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 13, 2025
    CISA deadline
    21 days
    CVSS severity
    4.4 (medium)
  1633. Rank 1643Samsung Mobile Devices (Galaxy)

    CVE-2023-21492

    Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2023
    CISA deadline
    21 days
    CVSS severity
    4.4 (medium)
  1634. Rank 1644Microsoft Windows

    CVE-2023-24880

    Ransomware

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 14, 2023
    CISA deadline
    21 days
    CVSS severity
    4.4 (medium)
  1635. Rank 1645Samsung Mobile Devices (Galaxy)

    CVE-2021-25370

    Samsung Mobile Devices Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    21 days
    CVSS severity
    4.4 (medium)
  1636. Rank 1646Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13374

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)
  1637. Rank 1647Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-0162

    CVE from 2016, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)
  1638. Rank 1648Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0059

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)
  1639. Rank 1649IBM Data Risk Manager

    CVE-2020-4430

    IBM Data Risk Manager Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    4.3 (medium)
  1640. Rank 1650Citrix NetScaler ADC / Gateway

    CVE-2020-8196

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    4.3 (medium)
  1641. Rank 1651Apple iOS / iPadOS

    CVE-2020-9819

    Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    4.3 (medium)
  1642. Rank 1652Apple iOS / iPadOS / macOS

    CVE-2025-43200

    Apple Multiple Products Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 16, 2025
    CISA deadline
    21 days
    CVSS severity
    4.2 (medium)
  1643. Rank 1653TeleMessage TM SGNL

    CVE-2025-48928

    TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 1, 2025
    CISA deadline
    21 days
    CVSS severity
    4.0 (medium)
  1644. Rank 1654VMware (Broadcom) VMware Tools

    CVE-2023-20867

    VMware Tools Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    3.9 (low)
  1645. Rank 1655Oracle Java SE (JRE / JDK)

    CVE-2013-2423

    CVE from 2013, added in 2022

    Oracle JRE Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    3.7 (low)
  1646. Rank 1656Arm Mali GPU (pilote noyau)

    CVE-2023-26083

    Arm Mali GPU Kernel Driver Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    3.3 (low)
  1647. Rank 1657Mitel MiCollab

    CVE-2024-55550

    Ransomware

    Mitel MiCollab Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    2.7 (low)

End of life: remove

These products are no longer supported by their vendor: no patch is coming. CISA asks that they be removed or isolated from the network. Sorted from most to least recently added.

  1. Sophos CyberoamOS (Cyberoam)

    CVE-2020-29574

    RansomwareEnd of lifeCVE from 2020, added in 2025

    CyberoamOS (CROS) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. NUUO NVRmini / NVRmini2

    CVE-2018-14933

    End of lifeCVE from 2018, added in 2024

    NUUO NVRmini Devices OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. NUUO NVRmini / NVRmini2

    CVE-2022-23227

    End of lifeCVE from 2022, added in 2024

    NUUO NVRmini2 Devices Missing Authentication Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-9379

    End of life

    Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  5. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-9380

    End of life

    Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  6. D-Link Routers (DIR, DWR, DSR)

    CVE-2023-25280

    End of life

    D-Link DIR-820 Router OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 30, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-8963

    End of life

    Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 19, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  8. Adobe Flash Player

    CVE-2013-0643

    End of lifeCVE from 2013, added in 2024

    Adobe Flash Player Incorrect Default Permissions Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  9. Adobe Flash Player

    CVE-2013-0648

    End of lifeCVE from 2013, added in 2024

    Adobe Flash Player Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  10. Adobe Flash Player

    CVE-2014-0497

    End of lifeCVE from 2014, added in 2024

    Adobe Flash Player Integer Underflow Vulnerablity

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show the other 62 end-of-life products
  1. Adobe Flash Player

    CVE-2014-0502

    End of lifeCVE from 2014, added in 2024

    Adobe Flash Player Double Free Vulnerablity

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  2. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-8190

    End of life

    Ivanti Cloud Services Appliance OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  3. Microsoft Internet Explorer / Edge (legacy)

    CVE-2012-4792

    End of lifeCVE from 2012, added in 2024

    Microsoft Internet Explorer Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jul 23, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. D-Link Routers (DIR, DWR, DSR)

    CVE-2014-100005

    End of lifeCVE from 2014, added in 2024

    D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  5. D-Link Routers (DIR, DWR, DSR)

    CVE-2021-40655

    End of lifeCVE from 2021, added in 2024

    D-Link DIR-605 Router Information Disclosure Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  6. D-Link NAS DNS (ShareCenter)

    CVE-2024-3272

    End of life

    D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. D-Link NAS DNS (ShareCenter)

    CVE-2024-3273

    End of life

    D-Link Multiple NAS Devices Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Linux Kernel

    CVE-2010-3904

    End of lifeCVE from 2010, added in 2023

    Linux Kernel Improper Input Validation Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  9. Linux Kernel

    CVE-2014-0196

    End of lifeCVE from 2014, added in 2023

    Linux Kernel Race Condition Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  10. Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3163

    End of lifeCVE from 2013, added in 2023

    Microsoft Internet Explorer Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  11. D-Link Routers (DIR, DWR, DSR)

    CVE-2011-4723

    End of lifeCVE from 2011, added in 2022

    D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    5.7 (medium)
  12. D-Link Routers (DIR, DWR, DSR)

    CVE-2022-26258

    End of life

    D-Link DIR-820L Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Delta Electronics DOPSoft 2

    CVE-2021-38406

    End of life

    Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  14. Adobe Flash Player

    CVE-2010-1297

    End of lifeCVE from 2010, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  15. Adobe Flash Player

    CVE-2011-0609

    End of lifeCVE from 2011, added in 2022

    Adobe Flash Player Unspecified Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  16. Adobe Flash Player

    CVE-2012-0754

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.1 (high)
  17. Adobe Flash Player

    CVE-2012-0767

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  18. Adobe Flash Player

    CVE-2012-5054

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  19. Microsoft Silverlight

    CVE-2013-0074

    RansomwareEnd of lifeCVE from 2013, added in 2022

    Microsoft Silverlight Double Dereference Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  20. Microsoft Silverlight

    CVE-2013-3896

    End of lifeCVE from 2013, added in 2022

    Microsoft Silverlight Information Disclosure Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  21. IBM InfoSphere BigInsights

    CVE-2013-3993

    RansomwareEnd of lifeCVE from 2013, added in 2022

    IBM InfoSphere BigInsights Invalid Input Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  22. Adobe Flash Player

    CVE-2014-8439

    End of lifeCVE from 2014, added in 2022

    Adobe Flash Player Dereferenced Pointer Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  23. Adobe Flash Player

    CVE-2015-0310

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player ASLR Bypass Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  24. Adobe Flash Player

    CVE-2015-8651

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  25. Microsoft Silverlight

    CVE-2016-0034

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Microsoft Silverlight Runtime Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  26. Adobe Flash Player

    CVE-2016-0984

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player and AIR Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  27. Adobe Flash Player

    CVE-2016-1010

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player and AIR Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  28. Kaseya VSA

    CVE-2017-18362

    RansomwareEnd of lifeCVE from 2017, added in 2022

    Kaseya VSA SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  29. Adobe Flash Player

    CVE-2018-5002

    End of lifeCVE from 2018, added in 2022

    Adobe Flash Player Stack-based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  30. Schneider Electric U.motion Builder

    CVE-2018-7841

    End of lifeCVE from 2018, added in 2022

    Schneider Electric U.motion Builder SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  31. D-Link NAS DNS (ShareCenter)

    CVE-2019-16057

    RansomwareEnd of lifeCVE from 2019, added in 2022

    D-Link DNS-320 Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  32. Adobe Flash Player

    CVE-2014-9163

    End of lifeCVE from 2014, added in 2022

    Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  33. Adobe Flash Player

    CVE-2015-0311

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  34. Adobe Flash Player

    CVE-2015-0313

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  35. Adobe Flash Player

    CVE-2015-3113

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  36. Adobe Flash Player

    CVE-2015-5122

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  37. Adobe Flash Player

    CVE-2015-5123

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  38. Checkbox Survey

    CVE-2021-27852

    End of life

    Checkbox Survey Deserialization of Untrusted Data Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  39. D-Link Routers (DIR, DWR, DSR)

    CVE-2021-45382

    End of life

    D-Link Multiple Routers Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 4, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  40. DASAN Zhone (DZS) Gigabit Passive Optical Network (GPON) Routers

    CVE-2018-10561

    End of lifeCVE from 2018, added in 2022

    Dasan GPON Routers Authentication Bypass Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  41. DASAN Zhone (DZS) Gigabit Passive Optical Network (GPON) Routers

    CVE-2018-10562

    RansomwareEnd of lifeCVE from 2018, added in 2022

    Dasan GPON Routers Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  42. Adobe Flash Player

    CVE-2012-2034

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  43. SonicWall SMA 100 (ex-SRA)

    CVE-2021-20028

    RansomwareEnd of life

    SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  44. D-Link and TRENDnet routers

    CVE-2015-1187

    End of lifeCVE from 2015, added in 2022

    D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  45. D-Link DCS cameras

    CVE-2016-11021

    End of lifeCVE from 2016, added in 2022

    D-Link DCS-930L Devices OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  46. Adobe Flash Player

    CVE-2016-4171

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  47. Adobe Flash Player

    CVE-2016-7892

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  48. NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-6334

    End of lifeCVE from 2017, added in 2022

    NETGEAR DGN2200 Devices OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  49. D-Link Routers (DIR, DWR, DSR)

    CVE-2019-16920

    End of lifeCVE from 2019, added in 2022

    D-Link Multiple Routers Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  50. D-Link Routers (DIR, DWR, DSR)

    CVE-2020-9377

    End of lifeCVE from 2020, added in 2022

    D-Link DIR-610 Devices Remote Command Execution

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  51. Adobe Flash Player

    CVE-2011-0611

    End of lifeCVE from 2011, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  52. Adobe Flash Player

    CVE-2012-1535

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  53. Adobe Flash Player

    CVE-2015-3043

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  54. Adobe Flash Player

    CVE-2015-5119

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  55. Adobe Flash Player

    CVE-2015-7645

    RansomwareEnd of lifeCVE from 2015, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  56. Adobe Flash Player

    CVE-2016-1019

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  57. Adobe Flash Player

    CVE-2016-4117

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  58. Adobe Flash Player

    CVE-2016-7855

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  59. Adobe Flash Player

    CVE-2017-11292

    End of lifeCVE from 2017, added in 2022

    Adobe Flash Player Type Confusion Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  60. Adobe Flash Player

    CVE-2018-15982

    RansomwareEnd of lifeCVE from 2018, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  61. D-Link Routers (DIR, DWR, DSR)

    CVE-2015-2051

    End of lifeCVE from 2015, added in 2022

    D-Link DIR-645 Router Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  62. Adobe Flash Player

    CVE-2018-4878

    RansomwareEnd of lifeCVE from 2018, added in 2021

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)

Sources: CISA KEV catalog (exploitation, dates added, required actions, ransomware), NVD (CVSS severity), CERT-FR (alerts), Microsoft (Microsoft patches). Brand and category: indicative classification by this site. Sources in detail.