Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,454 CVEs · Critical severity

CVEs (2,454, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 2,454 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2009-10007 CRITICAL Patched 9.1 2026-06-09 Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically chan…
CVE-2011-10043 CRITICAL Patched 9.8 2026-07-07 Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to sp…
CVE-2013-10075 CRITICAL Patched 9.1 2026-05-08 Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create…
CVE-2016-20096 CRITICAL 9.8 2026-07-21 Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by…
CVE-2017-20251 CRITICAL Patched 9.8 2026-06-09 WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injectin…
CVE-2018-25316 CRITICAL 9.8 2026-04-29 Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session val…
CVE-2018-25317 CRITICAL 9.8 2026-04-29 Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by…
CVE-2018-25318 CRITICAL 9.8 2026-04-29 Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cook…
CVE-2018-25320 CRITICAL 9.8 2026-05-17 ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECU…
CVE-2018-25332 CRITICAL Patched 9.8 2026-05-17 GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generat…
CVE-2018-25335 CRITICAL 9.8 2026-05-17 WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests …
CVE-2018-25350 CRITICAL 9.8 2026-05-23 userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUse…
CVE-2018-25357 CRITICAL Patched 9.8 2026-05-23 Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_n…
CVE-2018-25412 CRITICAL 9.8 2026-05-30 Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php …
CVE-2018-25427 CRITICAL 9.8 2026-06-01 Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or…
CVE-2018-25436 CRITICAL 9.8 2026-06-15 WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files…
CVE-2019-25727 CRITICAL 9.8 2026-06-04 WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating th…
CVE-2019-25729 CRITICAL 9.8 2026-06-04 PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the…
CVE-2019-25738 CRITICAL 9.8 2026-06-04 WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting th…
CVE-2019-25741 CRITICAL 9.8 2026-06-04 Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attacker…
CVE-2019-25763 CRITICAL 9.8 2026-06-20 WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the soc…
CVE-2020-37168 CRITICAL 9.8 2026-05-13 Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for paym…
CVE-2020-37228 CRITICAL 9.8 2026-05-16 iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode…
CVE-2020-37239 CRITICAL 9.8 2026-05-16 libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunk…
CVE-2021-47923 CRITICAL 9.8 2026-05-10 OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers c…