CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Critical
10,000 result(s) · page 1 of 500
CVE-2026-93467
CRITICAL

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously craft...

CVSS 9.8 2026-09-18
CVE-2026-85878
CRITICAL

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 2026-09-18
CVE-2026-69843
CRITICAL

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-18
CVE-2026-62874
CRITICAL

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-18
CVE-2026-87701
CRITICAL

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a net...

CVSS 9.6 2026-09-17
CVE-2026-85889
CRITICAL

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
CVE-2026-85885
CRITICAL

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 2026-09-17
CVE-2026-83944
CRITICAL

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
CVE-2026-77903
CRITICAL

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

CVSS 9 2026-09-17
CVE-2026-70200
CRITICAL

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
CVE-2026-70009
CRITICAL

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVSS 9.3 2026-09-17
CVE-2026-69865
CRITICAL

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

CVSS 10 2026-09-17
CVE-2026-69399
CRITICAL

Azure Arc Elevation of Privilege Vulnerability

CVSS 10 2026-09-17
CVE-2026-76949
CRITICAL

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victi...

CVSS 9.1 2026-09-17
CVE-2026-54767
CRITICAL

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave paramet...

CVSS 9.1 2026-09-17
CVE-2026-54734
CRITICAL

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using Http...

CVSS 10 2026-09-17
CVE-2026-54670
CRITICAL

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled ...

CVSS 9.1 2026-09-17
CVE-2026-54501
CRITICAL

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Br...

CVSS 9.4 2026-09-17
CVE-2026-54460
CRITICAL

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId an...

CVSS 9.8 2026-09-17
CVE-2026-54237
CRITICAL

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation ...

CVSS 9.3 2026-09-17
1 2 3 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.