Search
32,636 CVEs · Critical severity
CVEs (32,636, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 32,636 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27384 | CRITICAL | 9.0 | 2026-03-05 | Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.T… | |
| CVE-2025-66024 | CRITICAL | Patched | 9.0 | 2026-03-04 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) … |
| CVE-2026-24663 | CRITICAL | Patched | 9.0 | 2026-02-27 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by … |
| CVE-2026-27493 | CRITICAL | Patched | 9.0 | 2026-02-25 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form n… |
| CVE-2026-27822 | CRITICAL | 9.0 | 2026-02-25 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows… | |
| CVE-2026-0573 | CRITICAL | Patched | 9.0 | 2026-02-18 | An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repositor… |
| CVE-2025-69634 | CRITICAL | 9.0 | 2026-02-12 | Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is dispu… | |
| CVE-2026-20677 | CRITICAL | Patched | 9.0 | 2026-02-11 | A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4,… |
| CVE-2026-25881 | CRITICAL | Patched | 9.0 | 2026-02-09 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isG… |
| CVE-2025-68723 | CRITICAL | Patched | 9.0 | 2026-02-05 | Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file nam… |
| CVE-2026-24769 | CRITICAL | Patched | 9.0 | 2026-01-28 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in NocoDB’s attachment handlin… |
| CVE-2025-68015 | CRITICAL | 9.0 | 2026-01-22 | Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injecti… | |
| CVE-2026-24002 | CRITICAL | Patched | 9.0 | 2026-01-22 | Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be wo… |
| CVE-2026-23873 | CRITICAL | Patched | 9.0 | 2026-01-22 | hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through … |
| CVE-2026-1181 | CRITICAL | 9.0 | 2026-01-19 | Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from ot… | |
| CVE-2026-1009 | CRITICAL | 9.0 | 2026-01-15 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker … | |
| CVE-2026-23520 | CRITICAL | Patched | 9.0 | 2026-01-15 | Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.ge… |
| CVE-2025-12548 | CRITICAL | 9.0 | 2026-01-13 | A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, et… | |
| CVE-2025-59468 | CRITICAL | Patched | 9.0 | 2026-01-08 | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter. |
| CVE-2025-59469 | CRITICAL | Patched | 9.0 | 2026-01-08 | This vulnerability allows a Backup or Tape Operator to write files as root. |
| CVE-2025-59470 | CRITICAL | Patched | 9.0 | 2026-01-08 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. |
| CVE-2025-68929 | CRITICAL | Patched | 9.0 | 2025-12-29 | Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a s… |
| CVE-2025-66074 | CRITICAL | 9.0 | 2025-12-18 | Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through <= 3.3.8. | |
| CVE-2025-47372 | CRITICAL | 9.0 | 2025-12-18 | Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication. | |
| CVE-2025-33210 | CRITICAL | Patched | 9.0 | 2025-12-16 | NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution. |