Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,642 CVEs · Critical severity

CVEs (32,642, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 32,642 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-54117 CRITICAL Patched 9.0 2025-08-18 NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authe…
CVE-2025-44963 CRITICAL Patched 9.0 2025-08-04 RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
CVE-2025-44954 CRITICAL Patched 9.0 2025-08-04 RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
CVE-2025-8264 CRITICAL Patched 9.0 2025-07-29 Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious …
CVE-2025-53084 CRITICAL 9.0 2025-07-24 A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTT…
CVE-2025-24937 CRITICAL 9.0 2025-07-21 File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web a…
CVE-2025-24936 CRITICAL 9.0 2025-07-21 The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack an…
CVE-2025-54309 CRITICAL Patched 9.0 2025-07-18 CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admi…
CVE-2025-47158 CRITICAL 9.0 2025-07-18 Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-23266 CRITICAL 9.0 2025-07-17 NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elev…
CVE-2025-50067 CRITICAL 9.0 2025-07-15 Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vul…
CVE-2025-53835 CRITICAL Patched 9.0 2025-07-14 XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5…
CVE-2025-30023 CRITICAL Patched 9.0 2025-07-11 The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
CVE-2025-36038 CRITICAL Patched 9.0 2025-06-25 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
CVE-2025-49136 CRITICAL Patched 9.0 2025-06-09 listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functio…
CVE-2025-5086 CRITICAL Patched 9.0 2025-06-02 A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
CVE-2025-47933 CRITICAL Patched 9.0 2025-05-29 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf …
CVE-2025-48828 CRITICAL 9.0 2025-05-27 Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alte…
CVE-2025-31916 CRITICAL 9.0 2025-05-23 Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium allows Upload a Web Shell to a Web Server. This issu…
CVE-2025-30171 CRITICAL 9.0 2025-05-22 System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects A…
CVE-2024-48853 CRITICAL 9.0 2025-05-22 An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-E…
CVE-2025-48017 CRITICAL 9.0 2025-05-20 Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files
CVE-2025-35996 CRITICAL 9.0 2025-05-01 KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename …
CVE-2025-47154 CRITICAL 9.0 2025-05-01 LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute …
CVE-2025-46558 CRITICAL Patched 9.0 2025-04-30 XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, the Ma…