CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Critical
10,000 result(s) · page 499 of 500
CVE-2025-39975
CRITICAL

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_compound_op() In smb2_compound_op(), the loop that processes ea...

CVSS 9.8 2025-10-15
CVE-2023-7311
CRITICAL

BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is ec...

CVSS 9.3 2025-10-15
CVE-2023-7305
CRITICAL

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can s...

CVSS 9.2 2025-10-15
CVE-2023-7304
CRITICAL

Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected end...

CVSS 9.3 2025-10-15
CVE-2018-25117
CRITICAL

VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the...

CVSS 9.3 2025-10-15
CVE-2017-20205
CRITICAL

Valve's Source SDK (source-sdk-2013)'s ragdoll model parsing logic contains a stack-based buffer overflow vulnerability.The tokenizer function `nexttoken` copies characters from an...

CVSS 9.2 2025-10-15
CVE-2017-20204
CRITICAL

DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative interface that allows remote authentication as an undocum...

CVSS 9.3 2025-10-15
CVE-2011-10033
CRITICAL

The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter ...

CVSS 9.3 2025-10-15
CVE-2025-62376
CRITICAL

pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoint contains an improper authent...

CVSS 9.5 2025-10-14
CVE-2025-49553
CRITICAL

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in ...

CVSS 9.3 Adobe connect 2025-10-14
CVE-2025-34267
CRITICAL

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecu...

CVSS 9.9 Flowiseai flowise 2025-10-14
CVE-2025-11736
CRITICAL

A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. This manipulation of the argument ...

CVSS 9.8 Angeljudesuarez online_examination_system 2025-10-14
CVE-2025-59287
KEV CRITICAL

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVSS 9.8 Microsoft windows_server_2012 2025-10-14
CVE-2025-55315
CRITICAL

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

CVSS 9.9 Microsoft asp.net_core 2025-10-14
CVE-2025-54603
CRITICAL

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

CVSS 9 2025-10-14
CVE-2025-49708
CRITICAL

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 Microsoft windows_10_1809 2025-10-14
CVE-2025-11548
CRITICAL

A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Exe...

CVSS 9.3 2025-10-14
CVE-2025-49201
CRITICAL

A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, Forti...

CVSS 9.8 Fortinet fortipam 2025-10-14
CVE-2024-33507
CRITICAL

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1...

CVSS 9.1 Fortinet fortiisolator 2025-10-14
CVE-2025-9064
CRITICAL

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the p...

CVSS 9.1 Rockwellautomation factorytalk_view 2025-10-14
1 497 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.