CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Critical
10,000 result(s) · page 500 of 500
CVE-2025-9063
CRITICAL

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access t...

CVSS 9.8 Rockwellautomation factorytalk_view 2025-10-14
CVE-2025-7328
CRITICAL

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result...

CVSS 9.8 Rockwellautomation 1783-natr_firmware 2025-10-14
CVE-2025-11721
CRITICAL

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to...

CVSS 9.8 Mozilla firefox 2025-10-14
CVE-2025-11719
CRITICAL

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability w...

CVSS 9.8 Mozilla firefox 2025-10-14
CVE-2025-11717
CRITICAL

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Fire...

CVSS 9.1 Mozilla firefox 2025-10-14
CVE-2025-11710
CRITICAL

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerabilit...

CVSS 9.8 Mozilla firefox 2025-10-14
CVE-2025-11709
CRITICAL

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox ...

CVSS 9.8 Mozilla firefox 2025-10-14
CVE-2025-11708
CRITICAL

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

CVSS 9.8 Mozilla firefox 2025-10-14
CVE-2025-10610
CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure ...

CVSS 9.8 2025-10-14
CVE-2025-40771
CRITICAL

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIM...

CVSS 9.8 2025-10-14
CVE-2025-40765
CRITICAL

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerabilit...

CVSS 9.8 Siemens telecontrol_server_basic 2025-10-14
CVE-2025-46581
CRITICAL

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

CVSS 9.8 2025-10-14
CVE-2025-42937
CRITICAL

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-wr...

CVSS 9.8 2025-10-14
CVE-2025-42910
CRITICAL

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include exec...

CVSS 9 2025-10-14
CVE-2025-6919
CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License T...

CVSS 9.8 2025-10-13
CVE-2025-9976
CRITICAL

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an at...

CVSS 9 2025-10-13
CVE-2025-9265
CRITICAL

A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that...

CVSS 10 2025-10-13
CVE-2025-27258
CRITICAL

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

CVSS 9.8 Ericsson network_manager 2025-10-13
CVE-2025-11665
CRITICAL

A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulat...

CVSS 9.8 Dlink dap-2695_firmware 2025-10-13
CVE-2025-11664
CRITICAL

A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointmen...

CVSS 9.8 Campcodes online_beauty_parlor_management_system 2025-10-13
1 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.