Search
32,642 CVEs · Critical severity
CVEs (32,642, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 32,642 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29039 | CRITICAL | Patched | 9.0 | 2024-06-28 | tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML… |
| CVE-2024-37089 | CRITICAL | Patched | 9.0 | 2024-06-24 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.… |
| CVE-2024-37899 | CRITICAL | Patched | 9.0 | 2024-06-20 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is execut… |
| CVE-2024-0095 | CRITICAL | Patched | 9.0 | 2024-06-13 | NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a n… |
| CVE-2024-4371 | CRITICAL | Patched | 9.0 | 2024-06-13 | The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versio… |
| CVE-2024-35213 | CRITICAL | Patched | 9.0 | 2024-06-11 | An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service c… |
| CVE-2024-31401 | CRITICAL | Patched | 9.0 | 2024-06-11 | Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on… |
| CVE-2024-29855 | CRITICAL | Patched | 9.0 | 2024-06-11 | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator |
| CVE-2024-35677 | CRITICAL | Patched | 9.0 | 2024-06-10 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusion.This issue affects M… |
| CVE-2024-34551 | CRITICAL | Patched | 9.0 | 2024-06-04 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects S… |
| CVE-2024-33560 | CRITICAL | 9.0 | 2024-06-04 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This issue affects XStore: fro… | |
| CVE-2024-3300 | CRITICAL | 9.0 | 2024-05-30 | An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution. | |
| CVE-2024-31989 | CRITICAL | Patched | 9.0 | 2024-05-21 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the same cluster could… |
| CVE-2024-36053 | CRITICAL | 9.0 | 2024-05-19 | In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received… | |
| CVE-2024-31231 | CRITICAL | 9.0 | 2024-05-17 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub:… | |
| CVE-2023-32297 | CRITICAL | 9.0 | 2024-05-17 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS A… | |
| CVE-2024-2366 | CRITICAL | Patched | 9.0 | 2024-05-16 | A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/… |
| CVE-2024-32002 | CRITICAL | Patched | 9.0 | 2024-05-14 | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that ex… |
| CVE-2024-32964 | CRITICAL | Patched | 9.0 | 2024-05-14 | Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Ser… |
| CVE-2024-28075 | CRITICAL | Patched | 9.0 | 2024-05-14 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service res… |
| CVE-2024-0087 | CRITICAL | Patched | 9.0 | 2024-05-14 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to … |
| CVE-2023-38121 | CRITICAL | Patched | 9.0 | 2024-05-03 | Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … |
| CVE-2024-32971 | CRITICAL | Patched | 9.0 | 2024-05-02 | Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. The affected versions of Apollo Router contain a … |
| CVE-2024-4142 | CRITICAL | 9.0 | 2024-05-01 | An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with l… | |
| CVE-2024-33553 | CRITICAL | Patched | 9.0 | 2024-04-29 | Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5. |