An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary
An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary co
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).
Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's as
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-res
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privil
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated re
SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices c
AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Cam
Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to
Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing a
Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUser
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulner
The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthe
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote a
netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenat
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2
An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firm
An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information v
An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive info
An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive in
An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive
An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via t
Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Ob
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi S
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the
An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows atta
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to n
Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostn
DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca
The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerabl
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started