vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c.
sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The
hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. A
An unauthenticated attacker with access to the local network of the medical office can use known default credentials to
The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters w
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix memory corruption d
Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve th
The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS comm
SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed cont
An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control
DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into
An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retr
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofin
In the Linux kernel, the following vulnerability has been resolved: bpf: devmap: provide rxq after redirect rxq contai
In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix possible double free in smb2_set_e
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reli
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the N
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sen
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sen
Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks ac
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix race between laundromat and free_stateid
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s priv
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.ph
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.p
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Socia
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. W
SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authent
An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive informat
Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toa
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer al
Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a We
Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-buil
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started