Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pass
NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to cod
A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to a
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa
A remote code execution issue exists in HPE OneView.
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type com
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free
In the Linux kernel, the following vulnerability has been resolved: net: atlantic: fix fragment overflow handling in RX
In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_a
In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in
When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system with
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system witho
In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_requ
In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from non-linear x
An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. T
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to versi
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a
NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBL
TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to I
Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to ma
GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows att
Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PH
MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compar
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is
A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system in
The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and
A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functi
A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionalit
A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbi
A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/ht
A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESE
A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpLis
The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to
Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows si
ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish
The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2
The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers
The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ paramet
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of th
Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access
PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execu
Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a
Plesk 18.0 has Incorrect Access Control.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started