Search
7,864 CVEs · Critical severity
CVEs (7,864, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 7,864 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-22956 | CRITICAL | Patched | 9.8 | 2025-09-08 | OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState … |
| CVE-2025-52161 | CRITICAL | 9.8 | 2025-09-08 | Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| CVE-2025-57141 | CRITICAL | 9.8 | 2025-09-08 | rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc. | |
| CVE-2025-56266 | CRITICAL | 9.8 | 2025-09-08 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL. | |
| CVE-2025-56267 | CRITICAL | 9.8 | 2025-09-08 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file. | |
| CVE-2025-57285 | CRITICAL | 9.8 | 2025-09-08 | codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled direc… | |
| CVE-2025-9113 | CRITICAL | 9.8 | 2025-09-08 | The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_media' function in all vers… | |
| CVE-2025-9114 | CRITICAL | 9.8 | 2025-09-08 | The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin providing user-controlled… | |
| CVE-2025-58745 | CRITICAL | Patched | 9.9 | 2025-09-08 | WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIM… |
| CVE-2025-58746 | CRITICAL | 9.0 | 2025-09-08 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to ver… | |
| CVE-2025-42922 | CRITICAL | 9.9 | 2025-09-09 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when execut… | |
| CVE-2025-42944 | CRITICAL | 10.0 | 2025-09-09 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to a… | |
| CVE-2025-42958 | CRITICAL | 9.1 | 2025-09-09 | Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete… | |
| CVE-2025-10134 | CRITICAL | 9.1 | 2025-09-09 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_… | |
| CVE-2025-40795 | CRITICAL | Patched | 9.8 | 2025-09-09 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), Us… |
| CVE-2025-40804 | CRITICAL | 9.1 | 2025-09-09 | A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authenticat… | |
| CVE-2025-54236 | CRITICAL | 9.1 | 2025-09-09 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successf… | |
| CVE-2025-9994 | CRITICAL | 9.8 | 2025-09-09 | The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access. | |
| CVE-2025-10183 | CRITICAL | Patched | 9.1 | 2025-09-09 | A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an … |
| CVE-2025-54261 | CRITICAL | 10.0 | 2025-09-09 | ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability tha… | |
| CVE-2025-55232 | CRITICAL | Patched | 9.8 | 2025-09-09 | Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-57085 | CRITICAL | Patched | 9.8 | 2025-09-09 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Deni… |
| CVE-2025-55048 | CRITICAL | 9.8 | 2025-09-09 | Multiple CWE-78 | |
| CVE-2025-55049 | CRITICAL | 9.1 | 2025-09-09 | Use of Default Cryptographic Key (CWE-1394) | |
| CVE-2025-55050 | CRITICAL | 9.8 | 2025-09-09 | CWE-1242: Inclusion of Undocumented Features |