Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Bitcoin /
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing
Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in sear
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admi
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescriptio
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in a
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" pa
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/c
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overfl
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr
In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escal
Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academ
Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Info
The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including
The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including
The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in
ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to exec
An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a
A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor w
Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the
Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response h
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5
The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file
The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. Th
Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issu
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
Infoblox NIOS through 8.6.4 executes with more privileges than required.
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which ma
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/op
Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862
Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is
An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B
WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store
A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker t
In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On
In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Prevent changing BAR size/flags in pc
In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintain
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started