IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). libris
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 an
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosqui
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can retu
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper auth
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary comma
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to t
SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary c
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves
The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied outp
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input o
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, all
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /gofo
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wa
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started