A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as th
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected
An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t
Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when acc
AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an att
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via
Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the admini
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials i
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, a
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This v
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones
ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.
ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in
Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into
Memory corruption while parsing the ML IE due to invalid frame content.
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traver
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated
Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers
Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JW
A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without an
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures w
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager
Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveC
SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete a
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::ho
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limit
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attac
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send spe
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre.
The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versi
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a ne
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability
A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad act
Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileg
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started