Search
32,642 CVEs · Critical severity
CVEs (32,642, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 32,642 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59947 | CRITICAL | Patched | 9.0 | 2025-12-15 | NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and van… |
| CVE-2025-65267 | CRITICAL | 9.0 | 2025-12-03 | In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes wh… | |
| CVE-2025-3500 | CRITICAL | Patched | 9.0 | 2025-12-01 | Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. |
| CVE-2025-63729 | CRITICAL | 9.0 | 2025-11-25 | An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Clie… | |
| CVE-2025-64325 | CRITICAL | Patched | 9.0 | 2025-11-18 | Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipula… |
| CVE-2025-9501 | CRITICAL | Patched | 9.0 | 2025-11-17 | The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP co… |
| CVE-2025-36096 | CRITICAL | 9.0 | 2025-11-13 | IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacke… | |
| CVE-2025-64338 | CRITICAL | Patched | 9.0 | 2025-11-07 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Nam… |
| CVE-2025-62368 | CRITICAL | Patched | 9.0 | 2025-10-28 | Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due to unsafe deserializat… |
| CVE-2025-62023 | CRITICAL | 9.0 | 2025-10-22 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905. | |
| CVE-2025-42910 | CRITICAL | 9.0 | 2025-10-14 | Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could incl… | |
| CVE-2025-9976 | CRITICAL | 9.0 | 2025-10-13 | An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could all… | |
| CVE-2025-59978 | CRITICAL | Patched | 9.0 | 2025-10-09 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tag… |
| CVE-2025-56795 | CRITICAL | Patched | 9.0 | 2025-09-29 | Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of … |
| CVE-2025-20363 | CRITICAL | Patched | 9.0 | 2025-09-25 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Soft… |
| CVE-2025-59545 | CRITICAL | Patched | 9.0 | 2025-09-23 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of… |
| CVE-2025-48703 | CRITICAL | Patched | 9.0 | 2025-09-19 | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filema… |
| CVE-2025-58766 | CRITICAL | Patched | 9.0 | 2025-09-17 | Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbit… |
| CVE-2025-55113 | CRITICAL | Patched | 9.0 | 2025-09-16 | If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentiall… |
| CVE-2025-55109 | CRITICAL | Patched | 9.0 | 2025-09-16 | An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an emp… |
| CVE-2025-58746 | CRITICAL | 9.0 | 2025-09-08 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to ver… | |
| CVE-2025-55244 | CRITICAL | 9.0 | 2025-09-04 | Azure Bot Service Elevation of Privilege Vulnerability | |
| CVE-2025-53690 | CRITICAL | Patched | 9.0 | 2025-09-03 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience M… |
| CVE-2025-34157 | CRITICAL | Patched | 9.0 | 2025-08-27 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low pr… |
| CVE-2025-55205 | CRITICAL | Patched | 9.0 | 2025-08-18 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant u… |