Search
1,528 CVEs · Critical severity
CVEs (1,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,528 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43716 | CRITICAL | 9.8 | 2026-08-18 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB. | |
| CVE-2021-43717 | CRITICAL | 9.8 | 2026-08-18 | An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-c… | |
| CVE-2022-4993 | CRITICAL | 9.1 | 2026-08-13 | HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message t… | |
| CVE-2023-42179 | CRITICAL | 9.8 | 2026-08-26 | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. | |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |
| CVE-2024-11080 | CRITICAL | 9.8 | 2026-09-05 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in t… | |
| CVE-2024-13784 | CRITICAL | 9.8 | 2026-08-16 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via des… | |
| CVE-2024-27253 | CRITICAL | 10.0 | 2026-08-12 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | |
| CVE-2025-15688 | CRITICAL | 9.3 | 2026-08-20 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | |
| CVE-2025-15689 | CRITICAL | 9.8 | 2026-08-20 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | |
| CVE-2025-41769 | CRITICAL | 9.8 | 2026-08-12 | The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this… | |
| CVE-2025-51679 | CRITICAL | 9.1 | 2026-08-26 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. | |
| CVE-2025-59321 | CRITICAL | 9.8 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed vi… | |
| CVE-2025-59324 | CRITICAL | 9.1 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| CVE-2025-59326 | CRITICAL | 9.8 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from… | |
| CVE-2025-61163 | CRITICAL | 9.8 | 2026-08-26 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origi… | |
| CVE-2025-61165 | CRITICAL | 9.8 | 2026-08-26 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | |
| CVE-2025-67066 | CRITICAL | 9.8 | 2026-09-04 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |
| CVE-2025-70290 | CRITICAL | Patched | 9.8 | 2026-08-26 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The i… |
| CVE-2025-70293 | CRITICAL | Patched | 9.8 | 2026-08-26 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allo… |
| CVE-2025-9314 | CRITICAL | 9.8 | 2026-09-02 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | |
| CVE-2026-10196 | CRITICAL | Patched | 9.8 | 2026-09-05 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… |
| CVE-2026-10522 | CRITICAL | 9.8 | 2026-08-29 | The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attac… | |
| CVE-2026-10579 | CRITICAL | 9.8 | 2026-08-11 | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed at… | |
| CVE-2026-11613 | CRITICAL | 9.8 | 2026-09-04 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter paramet… |