Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authe
MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication,
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messag
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database ba
webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows aut
LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows r
Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute
CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through c
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to ove
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to ove
Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers t
GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malic
StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace()
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk e
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadm
Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive app
FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly s
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut
FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-code
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled'
A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg
A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists i
TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /
SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows
An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of
YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) c
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics a
Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerab
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFor
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ whic
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odo
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulner
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid i
Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists
An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password b
A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started