Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,642 CVEs · Critical severity

CVEs (32,642, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 32,642 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-59947 CRITICAL Patched 9.0 2025-12-15 NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and van…
CVE-2025-65267 CRITICAL 9.0 2025-12-03 In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes wh…
CVE-2025-3500 CRITICAL Patched 9.0 2025-12-01 Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.
CVE-2025-63729 CRITICAL 9.0 2025-11-25 An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Clie…
CVE-2025-64325 CRITICAL Patched 9.0 2025-11-18 Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipula…
CVE-2025-9501 CRITICAL Patched 9.0 2025-11-17 The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP co…
CVE-2025-36096 CRITICAL 9.0 2025-11-13 IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacke…
CVE-2025-64338 CRITICAL Patched 9.0 2025-11-07 ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Nam…
CVE-2025-62368 CRITICAL Patched 9.0 2025-10-28 Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due to unsafe deserializat…
CVE-2025-62023 CRITICAL 9.0 2025-10-22 Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905.
CVE-2025-42910 CRITICAL 9.0 2025-10-14 Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could incl&hellip;
CVE-2025-9976 CRITICAL 9.0 2025-10-13 An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could all&hellip;
CVE-2025-59978 CRITICAL Patched 9.0 2025-10-09 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tag&hellip;
CVE-2025-56795 CRITICAL Patched 9.0 2025-09-29 Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of &hellip;
CVE-2025-20363 CRITICAL Patched 9.0 2025-09-25 A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Soft&hellip;
CVE-2025-59545 CRITICAL Patched 9.0 2025-09-23 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of&hellip;
CVE-2025-48703 CRITICAL Patched 9.0 2025-09-19 CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filema&hellip;
CVE-2025-58766 CRITICAL Patched 9.0 2025-09-17 Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbit&hellip;
CVE-2025-55113 CRITICAL Patched 9.0 2025-09-16 If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentiall&hellip;
CVE-2025-55109 CRITICAL Patched 9.0 2025-09-16 An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an emp&hellip;
CVE-2025-58746 CRITICAL 9.0 2025-09-08 The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to ver&hellip;
CVE-2025-55244 CRITICAL 9.0 2025-09-04 Azure Bot Service Elevation of Privilege Vulnerability
CVE-2025-53690 CRITICAL Patched 9.0 2025-09-03 Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience M&hellip;
CVE-2025-34157 CRITICAL Patched 9.0 2025-08-27 Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low pr&hellip;
CVE-2025-55205 CRITICAL Patched 9.0 2025-08-18 Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant u&hellip;