Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 232/432
10.0
CVE-2024-45032

A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Managemen

9.1
CVE-2024-35783

A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions

9.8
CVE-2024-33698

A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SI

9.8
CVE-2024-6596

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users c

9.8
CVE-2024-6342

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versi

9.8
CVE-2024-44411

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

9.8
CVE-2024-44410

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

10.0
CVE-2024-6795

In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an un

9.8
CVE-2024-44902

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

9.3
CVE-2024-42500

HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

9.8
CVE-2024-44849

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

9.8
CVE-2024-44721

SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

9.6
CVE-2024-40643

Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by

9.8
CVE-2024-7015

Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authent

9.9
CVE-2024-37288

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document con

9.8
CVE-2024-8584

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to

9.8
CVE-2024-6928

The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a

9.8
CVE-2024-6924

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL

9.8
CVE-2024-40711 KEV

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec

9.9
CVE-2024-39714

A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to re

9.9
CVE-2024-38650

An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on

9.8
CVE-2024-45771

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin

9.8
CVE-2024-44839

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.

9.8
CVE-2024-44838

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin

9.8
CVE-2024-8517

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacke

9.1
CVE-2024-45758

H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file r

9.8
CVE-2024-44402

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

9.8
CVE-2024-44401

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

9.8
CVE-2024-7493

The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.

9.8
CVE-2024-8292

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/accoun

9.8
CVE-2024-8395

FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside atta

9.8
CVE-2024-45159

An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the

9.8
CVE-2024-45158

An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_

10.0
CVE-2024-7591

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMa

9.8
CVE-2024-44727

Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/lo

9.3
CVE-2024-24759

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat ac

9.1
CVE-2024-42885

SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id param

9.8
CVE-2024-8470

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j

9.8
CVE-2024-8469

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport

9.8
CVE-2024-8468

SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /job

9.8
CVE-2024-8467

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport

9.8
CVE-2024-8466

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j

9.8
CVE-2024-8465

SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jo

9.8
CVE-2024-8464

SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /j

9.9
CVE-2024-8463

File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an auth

10.0
CVE-2024-43102

Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM

9.8
CVE-2024-44998

In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx

9.8
CVE-2024-44985

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UAF in ip6_xmit() If skb_ex

10.0
CVE-2024-44984

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT

9.8
CVE-2024-44970

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlin

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started