Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DirectIQ DirectIQ
Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects A
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoinWebs Classiera
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett Lifte
Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - Wo
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely am
Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought T
The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take
The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue af
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W
yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.
yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered tha
Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the use
Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.
An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execut
Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi
An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the manageme
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor m
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upl
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywher
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Ga
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password
Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1.
Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been ide
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacke
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability wh
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-A
Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm.
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started