Search
32,642 CVEs · Critical severity
CVEs (32,642, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 32,642 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54117 | CRITICAL | Patched | 9.0 | 2025-08-18 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authe… |
| CVE-2025-44963 | CRITICAL | Patched | 9.0 | 2025-08-04 | RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key. |
| CVE-2025-44954 | CRITICAL | Patched | 9.0 | 2025-08-04 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account. |
| CVE-2025-8264 | CRITICAL | Patched | 9.0 | 2025-07-29 | Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious … |
| CVE-2025-53084 | CRITICAL | 9.0 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTT… | |
| CVE-2025-24937 | CRITICAL | 9.0 | 2025-07-21 | File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web a… | |
| CVE-2025-24936 | CRITICAL | 9.0 | 2025-07-21 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack an… | |
| CVE-2025-54309 | CRITICAL | Patched | 9.0 | 2025-07-18 | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admi… |
| CVE-2025-47158 | CRITICAL | 9.0 | 2025-07-18 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2025-23266 | CRITICAL | 9.0 | 2025-07-17 | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elev… | |
| CVE-2025-50067 | CRITICAL | 9.0 | 2025-07-15 | Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vul… | |
| CVE-2025-53835 | CRITICAL | Patched | 9.0 | 2025-07-14 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5… |
| CVE-2025-30023 | CRITICAL | Patched | 9.0 | 2025-07-11 | The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack. |
| CVE-2025-36038 | CRITICAL | Patched | 9.0 | 2025-06-25 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. |
| CVE-2025-49136 | CRITICAL | Patched | 9.0 | 2025-06-09 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functio… |
| CVE-2025-5086 | CRITICAL | Patched | 9.0 | 2025-06-02 | A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution. |
| CVE-2025-47933 | CRITICAL | Patched | 9.0 | 2025-05-29 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf … |
| CVE-2025-48828 | CRITICAL | 9.0 | 2025-05-27 | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alte… | |
| CVE-2025-31916 | CRITICAL | 9.0 | 2025-05-23 | Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium allows Upload a Web Shell to a Web Server. This issu… | |
| CVE-2025-30171 | CRITICAL | 9.0 | 2025-05-22 | System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects A… | |
| CVE-2024-48853 | CRITICAL | 9.0 | 2025-05-22 | An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-E… | |
| CVE-2025-48017 | CRITICAL | 9.0 | 2025-05-20 | Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files | |
| CVE-2025-35996 | CRITICAL | 9.0 | 2025-05-01 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename … | |
| CVE-2025-47154 | CRITICAL | 9.0 | 2025-05-01 | LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute … | |
| CVE-2025-46558 | CRITICAL | Patched | 9.0 | 2025-04-30 | XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, the Ma… |