Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to res
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Seq
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template p
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: Initialize ctx to avoid
In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_
In the Linux kernel, the following vulnerability has been resolved: Revert "smb: client: fix TCP timers deadlock after
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusio
Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-wo
In the Linux kernel, the following vulnerability has been resolved: netfilter: socket: Lookup orig tuple for IPv6 SNAT
A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker
NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting f
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This i
An attacker can upload an arbitrary file instead of a plant image.
Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces o
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported version
Argo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify Eve
Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service co
An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the s
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the co
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th
Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affe
Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protob
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used t
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arb
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is
A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password
Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Inje
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users
Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.Thi
Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Produc
Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analy
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Produ
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started