CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
PaperCut MF/NG: Authentication Bypass
Improper Control of Generation of Code ('Code Injection') in GitLab
Adobe Commerce | Incorrect Authorization (CWE-863)
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiS…
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to…
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-le…
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
LiteLLM: Authenticated command execution via MCP stdio test endpoints
WebPros cPanel and WHM Authentication Bypass via Login Flow
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability
chromium-browser: Use after free in CSS
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Showing 1 to 25 CVEs · page 1 (more available)