Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenti
Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public
An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbintera
Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a direct
A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community pa
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive informa
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive informa
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to t
A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injectin
Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted
SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted sc
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, inc
Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achi
An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the val
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote at
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management
Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.jso
There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG
Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via th
A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx pa
An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLA
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLA
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or outp
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS expo
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sa
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticate
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that wo
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was id
pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to c
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default
The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Di
CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad
CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transm
CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffe
An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeout on deleted connect
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word
An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started