OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0
The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
In the Linux kernel, the following vulnerability has been resolved: tunnels: fix kasan splat when generating ipv4 pmtu
In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The i
In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are b
In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_len
In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data
In the Linux kernel, the following vulnerability has been resolved: smb: client: let smbd_destroy() call disable_work_s
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptograph
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user
The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authoriza
The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Incl
The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a
An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may all
The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL In
WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability whi
The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falco
The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authenticat
SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u
SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param
In the Linux kernel, the following vulnerability has been resolved: tipc: do not update mtu if msg_max is too small in
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from
The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in version
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that
NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An a
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumente
The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function
Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remo
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started