When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnera
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerabil
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerab
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly di
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauth
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulne
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow
Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may
Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may
Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the use
CMSimple 5.16 allows the user to edit log.php file via print page.
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter i
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, ma
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, ma
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and i
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visio
The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A
Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, auth
A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute ar
A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to exec
Deserialization of Untrusted Data vulnerability in Pdfcrowd Dev Team Save as PDF save-as-pdf-by-pdfcrowd allows Object I
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology
DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, whic
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",whi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping
Deserialization of Untrusted Data vulnerability in ThimPress FundPress fundpress allows Object Injection.This issue affe
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in th
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT mess
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the under
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a
In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19
A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises bec
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inline
An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started