The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to
WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v
WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web reque
Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a W
Cross-Site Request Forgery (CSRF) vulnerability in Mike Selander WP Options Editor wp-options-editor allows Privilege Es
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the for
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer fu
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCf
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName fu
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientSt
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated at
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability coul
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attac
The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to creat
HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service
Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in t
Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS
An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account witho
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course B
Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-cont
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix TCP options overflow. Syzbot reported t
In the Linux kernel, the following vulnerability has been resolved: netrom: check buffer length before accessing it Sy
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NO
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table
Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address edit
Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations i
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless netw
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address upda
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless ne
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started