Search
1,115 CVEs · Critical severity
CVEs (1,115, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,115 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-10043 | CRITICAL | Patched | 9.8 | 2026-07-07 | Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to sp… |
| CVE-2016-20096 | CRITICAL | 9.8 | 2026-07-21 | Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by… | |
| CVE-2022-50973 | CRITICAL | 9.8 | 2026-07-02 | Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload a… | |
| CVE-2023-49899 | CRITICAL | 9.8 | 2026-07-16 | An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel. | |
| CVE-2023-49900 | CRITICAL | 9.8 | 2026-07-16 | An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. | |
| CVE-2024-14037 | CRITICAL | 9.8 | 2026-07-02 | Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through… | |
| CVE-2024-23564 | CRITICAL | 9.1 | 2026-07-17 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to th… | |
| CVE-2024-51311 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. | |
| CVE-2024-51312 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. | |
| CVE-2024-51313 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. | |
| CVE-2024-51314 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. | |
| CVE-2024-51315 | CRITICAL | 9.8 | 2026-07-20 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName | |
| CVE-2024-58354 | CRITICAL | 9.9 | 2026-07-23 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_req… | |
| CVE-2025-11919 | CRITICAL | 9.6 | 2026-06-26 | The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). … | |
| CVE-2025-15646 | CRITICAL | Patched | 9.8 | 2026-07-01 | HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tr… |
| CVE-2025-23350 | CRITICAL | 9.0 | 2026-07-01 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft… | |
| CVE-2025-23351 | CRITICAL | 9.0 | 2026-07-01 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by craft… | |
| CVE-2025-51677 | CRITICAL | 9.1 | 2026-07-17 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior. | |
| CVE-2025-53827 | CRITICAL | Patched | 9.1 | 2026-07-06 | ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownC… |
| CVE-2025-53830 | CRITICAL | Patched | 9.1 | 2026-07-06 | Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 a… |
| CVE-2025-55017 | CRITICAL | Patched | 9.1 | 2026-06-26 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, fro… |
| CVE-2025-64152 | CRITICAL | Patched | 9.1 | 2026-06-26 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, fro… |
| CVE-2025-65720 | CRITICAL | 9.8 | 2026-07-15 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | |
| CVE-2025-66390 | CRITICAL | 9.8 | 2026-07-21 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the re… | |
| CVE-2025-71327 | CRITICAL | 9.1 | 2026-06-25 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. … |