Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) ca
SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary cod
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.
Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.
CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that c
Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Withi
In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is zeroe
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release
In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in in
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd4_deleg_getattr_conflict in presence
A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could
The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive informati
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 pr
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a mal
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious e
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chai
No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: t
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploite
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a J
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter o
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parame
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports
In the Linux kernel, the following vulnerability has been resolved: nvme: move stopping keep-alive into nvme_uninit_ctr
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request mes
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the pub
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that o
A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabl
A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist s
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authenticati
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,
An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database reco
Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability v
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecti
Azure Stack Hub Elevation of Privilege Vulnerability
Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or mal
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrar
Loftware Spectrum through 4.6 has unprotected JMX Registry.
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run
Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started