Search
32,642 CVEs · Critical severity
CVEs (32,642, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 32,642 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52975 | CRITICAL | 9.0 | 2025-01-23 | An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive … | |
| CVE-2025-23061 | CRITICAL | Patched | 9.0 | 2025-01-15 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix f… |
| CVE-2024-54142 | CRITICAL | Patched | 9.0 | 2025-01-14 | Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations into posts, if the conversation had HTML entities tho… |
| CVE-2024-49375 | CRITICAL | Patched | 9.0 | 2025-01-14 | Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotel… |
| CVE-2025-23025 | CRITICAL | Patched | 9.0 | 2025-01-14 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, a… |
| CVE-2024-39604 | CRITICAL | 9.0 | 2025-01-14 | A command execution vulnerability exists in the update_filter_url.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitr… | |
| CVE-2024-39273 | CRITICAL | 9.0 | 2025-01-14 | A firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmwar… | |
| CVE-2024-48886 | CRITICAL | Patched | 9.0 | 2025-01-14 | A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7… |
| CVE-2024-47572 | CRITICAL | Patched | 9.0 | 2025-01-14 | An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipula… |
| CVE-2025-0282 | CRITICAL | 9.0 | 2025-01-08 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before ver… | |
| CVE-2024-51466 | CRITICAL | Patched | 9.0 | 2024-12-20 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could ex… |
| CVE-2024-55884 | CRITICAL | 9.0 | 2024-12-12 | In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-… | |
| CVE-2024-10773 | CRITICAL | 9.0 | 2024-12-06 | The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden u… | |
| CVE-2024-6516 | CRITICAL | Patched | 9.0 | 2024-12-05 | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products: ABB ASPECT - Enterp… |
| CVE-2024-28038 | CRITICAL | 9.0 | 2024-11-26 | The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSE… | |
| CVE-2024-11666 | CRITICAL | Patched | 9.0 | 2024-11-24 | Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since pe… |
| CVE-2024-52300 | CRITICAL | Patched | 9.0 | 2024-11-13 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can … |
| CVE-2024-43415 | CRITICAL | 9.0 | 2024-11-12 | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenti… | |
| CVE-2024-45764 | CRITICAL | Patched | 9.0 | 2024-11-08 | Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could … |
| CVE-2024-47460 | CRITICAL | 9.0 | 2024-11-05 | Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI … | |
| CVE-2023-29125 | CRITICAL | Patched | 9.0 | 2024-11-05 | A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700. |
| CVE-2024-23309 | CRITICAL | 9.0 | 2024-10-30 | The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authenticati… | |
| CVE-2024-6581 | CRITICAL | 9.0 | 2024-10-29 | A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the s… | |
| CVE-2024-26519 | CRITICAL | 9.0 | 2024-10-22 | An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi component. | |
| CVE-2024-38002 | CRITICAL | Patched | 9.0 | 2024-10-22 | The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3… |