Search
34,969 CVEs · Critical severity
CVEs (34,969, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 34,969 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32973 | CRITICAL | Patched | 9.0 | 2025-04-30 | XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, whe… |
| CVE-2025-32974 | CRITICAL | Patched | 9.0 | 2025-04-30 | XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider… |
| CVE-2024-56156 | CRITICAL | Patched | 9.0 | 2025-04-25 | Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enable… |
| CVE-2025-32911 | CRITICAL | 9.0 | 2025-04-15 | A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause … | |
| CVE-2025-32743 | CRITICAL | 9.0 | 2025-04-10 | In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attac… | |
| CVE-2024-58136 | CRITICAL | Patched | 9.0 | 2025-04-10 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through A… |
| CVE-2025-30406 | CRITICAL | Patched | 9.0 | 2025-04-03 | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as e… |
| CVE-2025-22457 | CRITICAL | Patched | 9.0 | 2025-04-03 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.… |
| CVE-2025-30095 | CRITICAL | Patched | 9.0 | 2025-03-31 | VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different inst… |
| CVE-2025-30472 | CRITICAL | Patched | 9.0 | 2025-03-22 | Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c… |
| CVE-2025-2311 | CRITICAL | Patched | 9.0 | 2025-03-20 | Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies Se… |
| CVE-2024-8017 | CRITICAL | Patched | 9.0 | 2025-03-20 | An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attack… |
| CVE-2025-29783 | CRITICAL | Patched | 9.0 | 2025-03-19 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over … |
| CVE-2025-27407 | CRITICAL | 9.0 | 2025-03-12 | graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a m… | |
| CVE-2025-27507 | CRITICAL | Patched | 9.0 | 2025-03-04 | The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Re… |
| CVE-2025-26206 | CRITICAL | 9.0 | 2025-03-03 | Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component | |
| CVE-2025-27590 | CRITICAL | Patched | 9.0 | 2025-03-03 | In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web. |
| CVE-2025-23115 | CRITICAL | 9.0 | 2025-03-01 | A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras management network. | |
| CVE-2024-52577 | CRITICAL | Patched | 9.0 | 2025-02-14 | In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited i… |
| CVE-2025-21198 | CRITICAL | Patched | 9.0 | 2025-02-11 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability |
| CVE-2024-39272 | CRITICAL | 9.0 | 2025-02-06 | A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to… | |
| CVE-2025-23114 | CRITICAL | 9.0 | 2025-02-05 | A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to proper… | |
| CVE-2024-55227 | CRITICAL | 9.0 | 2025-01-27 | A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payl… | |
| CVE-2024-55228 | CRITICAL | 9.0 | 2025-01-27 | A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload in… | |
| CVE-2024-52975 | CRITICAL | 9.0 | 2025-01-23 | An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive … |