CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Critical
10,000 result(s) · page 4 of 500
CVE-2026-15688
CRITICAL

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate ...

CVSS 9.2 2026-09-17
CVE-2026-88795
CRITICAL

The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it...

CVSS 9 2026-09-17
CVE-2026-86710
CRITICAL

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows...

CVSS 9.8 2026-09-17
CVE-2026-86709
CRITICAL

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any u...

CVSS 9.8 2026-09-17
CVE-2026-86707
CRITICAL

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead...

CVSS 9.8 2026-09-17
CVE-2026-87796
CRITICAL

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due...

CVSS 9.8 2026-09-17
CVE-2026-61594
CRITICAL

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a m...

CVSS 9.1 2026-09-16
CVE-2026-92805
CRITICAL

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers ...

CVSS 9.8 2026-09-16
CVE-2026-92787
CRITICAL

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified ...

CVSS 9.8 2026-09-16
CVE-2026-76460
KEV CRITICAL

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insuffic...

CVSS 10 Cisco identity_services_engine 2026-09-16
CVE-2026-75513
CRITICAL

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, pote...

CVSS 9.1 2026-09-16
CVE-2026-20332
CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Softwar...

CVSS 9.9 2026-09-16
CVE-2026-20284
CRITICAL

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient valida...

CVSS 9.1 2026-09-16
CVE-2025-56563
CRITICAL

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it t...

CVSS 9.8 2026-09-16
CVE-2026-92808
CRITICAL

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue...

CVSS 10 2026-09-16
CVE-2026-88592
CRITICAL

kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host wh...

CVSS 9.1 2026-09-16
CVE-2026-89083
CRITICAL

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain...

CVSS 9.3 2026-09-16
CVE-2026-89082
CRITICAL

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain...

CVSS 9.3 2026-09-16
CVE-2026-76423
CRITICAL

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerab...

CVSS 10 2026-09-16
CVE-2026-20341
CRITICAL

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. Th...

CVSS 9.1 2026-09-16
1 2 3 4 5 6 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.