CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Critical
10,000 result(s) · page 9 of 500
CVE-2026-15638
CRITICAL

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not ...

CVSS 9.1 2026-09-16
CVE-2026-81855
CRITICAL

A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.

CVSS 9.1 2026-09-15
CVE-2026-78225
CRITICAL

A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

CVSS 9 2026-09-15
CVE-2026-73807
CRITICAL

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could e...

CVSS 9.8 2026-09-15
CVE-2026-73437
CRITICAL

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP...

CVSS 9.6 2026-09-15
CVE-2026-61560
CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication....

CVSS 9.8 2026-09-15
CVE-2026-91749
CRITICAL

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chro...

CVSS 9.6 2026-09-15
CVE-2026-91939
CRITICAL

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP clas...

CVSS 9.8 2026-09-15
CVE-2026-91738
CRITICAL

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML pa...

CVSS 9.6 Google chrome 2026-09-15
CVE-2026-91729
CRITICAL

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox v...

CVSS 9.6 Google chrome 2026-09-15
CVE-2026-91728
CRITICAL

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security se...

CVSS 9.6 Google chrome 2026-09-15
CVE-2026-91718
CRITICAL

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security s...

CVSS 9.6 Google chrome 2026-09-15
CVE-2026-91716
CRITICAL

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security s...

CVSS 9.6 Google chrome 2026-09-15
CVE-2026-91710
CRITICAL

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium ...

CVSS 9.6 Google chrome 2026-09-15
CVE-2026-68491
CRITICAL

An insufficient check allowed for the overwrite of arbitrary files via a symlink.

CVSS 9.4 2026-09-15
CVE-2026-66890
CRITICAL

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

CVSS 9.6 2026-09-15
CVE-2026-66887
CRITICAL

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

CVSS 9.6 2026-09-15
CVE-2026-61568
CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist...

CVSS 9.6 2026-09-15
CVE-2026-61559
CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=t...

CVSS 9.6 2026-09-15
CVE-2026-54337
CRITICAL

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overw...

CVSS 9.8 2026-09-15
1 7 8 9 10 11 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.