Search
6,131 CVEs · Critical severity
CVEs (6,131, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 6,131 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-41240 | CRITICAL | 10.0 | 2025-07-24 | Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versio… | |
| CVE-2025-7437 | CRITICAL | 9.8 | 2025-07-24 | The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to… | |
| CVE-2025-7852 | CRITICAL | 9.8 | 2025-07-24 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_… | |
| CVE-2025-6380 | CRITICAL | 9.8 | 2025-07-24 | The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0.… | |
| CVE-2025-6441 | CRITICAL | 9.8 | 2025-07-24 | The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login… | |
| CVE-2025-4822 | CRITICAL | Patched | 9.8 | 2025-07-24 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection. Thi… |
| CVE-2025-5243 | CRITICAL | Patched | 10.0 | 2025-07-24 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software In… |
| CVE-2025-4784 | CRITICAL | Patched | 9.8 | 2025-07-24 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection. This issue affects Tourtella:… |
| CVE-2025-41420 | CRITICAL | 9.6 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted… | |
| CVE-2025-46410 | CRITICAL | 9.6 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A… | |
| CVE-2025-50128 | CRITICAL | 9.6 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially c… | |
| CVE-2025-53084 | CRITICAL | 9.0 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTT… | |
| CVE-2025-6260 | CRITICAL | 9.8 | 2025-07-24 | The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the … | |
| CVE-2025-7404 | CRITICAL | Patched | 9.8 | 2025-07-24 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This … |
| CVE-2025-32429 | CRITICAL | Patched | 9.8 | 2025-07-24 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2… |
| CVE-2025-54379 | CRITICAL | Patched | 9.8 | 2025-07-24 | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical … |
| CVE-2015-10143 | CRITICAL | Patched | 9.8 | 2025-07-25 | The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_sa… |
| CVE-2019-25224 | CRITICAL | Patched | 9.8 | 2025-07-25 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticat… |
| CVE-2025-45777 | CRITICAL | 9.8 | 2025-07-25 | An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request. | |
| CVE-2014-125117 | CRITICAL | 9.8 | 2025-07-25 | A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially cra… | |
| CVE-2025-29628 | CRITICAL | Patched | 9.4 | 2025-07-25 | A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.… |
| CVE-2025-29629 | CRITICAL | Patched | 9.1 | 2025-07-25 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell… |
| CVE-2025-29631 | CRITICAL | Patched | 9.8 | 2025-07-25 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable me… |
| CVE-2025-46199 | CRITICAL | Patched | 9.8 | 2025-07-25 | Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields |
| CVE-2025-30135 | CRITICAL | 9.4 | 2025-07-25 | An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RT… |