CVE Vulnerability Database

Search and browse 394,712 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2020-37253HIGH8.5Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attac...
CVE-2020-37252HIGH8.5Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows loca...
CVE-2020-37251HIGH8.5RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows lo...
CVE-2020-37250HIGH8.5TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows lo...
CVE-2019-25747HIGH8.5Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attack...
CVE-2016-20095HIGH8.5Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService an...
CVE-2016-20094HIGH8.5AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYS...
CVE-2016-20093HIGH8.5Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and...
CVE-2016-20092HIGH8.5NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows l...
CVE-2016-20091HIGH8.5Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate...
CVE-2016-20090HIGH8.5Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater serv...
CVE-2016-20089HIGH8.5Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code w...
CVE-2016-20088HIGH8.5Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that...
CVE-2016-20087HIGH8.5Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code...
CVE-2016-20086HIGH8.5Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer servi...
CVE-2016-20085HIGH8.5Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attack...
CVE-2026-9143MEDIUM5.3There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co...
CVE-2026-9142CRITICAL9.3There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s...
CVE-2026-4027HIGH7.1A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized acces...
CVE-2026-4026HIGH8.7A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit...
CVE-2026-49872HIGH8.1Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can po...
CVE-2026-49871CRITICAL9.3Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows...
CVE-2026-49357HIGH8.8Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o...
CVE-2026-49231MEDIUM5.4Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upst...
CVE-2026-49230CRITICAL9.1Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default confi...