Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 236/432
9.1
CVE-2024-27185

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

9.8
CVE-2024-43404

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT version

9.0
CVE-2024-35540

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or

9.8
CVE-2024-30949

An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday f

9.8
CVE-2024-33872

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code executio

9.8
CVE-2024-42575

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter

9.8
CVE-2024-42574

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter

9.8
CVE-2024-42573

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter

9.8
CVE-2024-42572

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter

9.8
CVE-2024-42571

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter

9.8
CVE-2024-42570

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter

9.8
CVE-2024-42569

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter

9.8
CVE-2024-42568

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport paramet

9.8
CVE-2024-42567

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at

9.8
CVE-2024-42566

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password paramete

9.8
CVE-2024-42565

ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/co

9.8
CVE-2024-42563

An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a c

9.8
CVE-2024-42562

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number

9.8
CVE-2024-42559

An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authent

9.8
CVE-2024-42558

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter

9.8
CVE-2024-42556

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type paramet

9.8
CVE-2024-43202

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2.

9.8
CVE-2024-6847

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it

9.0
CVE-2024-7777

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil

10.0
CVE-2024-5932

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all

9.8
CVE-2024-43354

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through

9.8
CVE-2024-43311

Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affec

9.8
CVE-2024-42815

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the

9.8
CVE-2024-42813

In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for th

9.8
CVE-2024-42812

In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID fi

9.6
CVE-2024-43261

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

9.0
CVE-2024-43252

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a

9.9
CVE-2024-43249

Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This iss

9.8
CVE-2024-43245

Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch

9.0
CVE-2024-43242

Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue aff

9.0
CVE-2024-43401

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without

9.0
CVE-2024-43400

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible

9.4
CVE-2024-43240

Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultim

9.8
CVE-2024-42658

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v

10.0
CVE-2024-37099

Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP:

9.8
CVE-2024-6330

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files

9.8
CVE-2024-44076

In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.

9.8
CVE-2024-42285

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-after-free related to destroyi

9.1
CVE-2024-42284

In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str(

9.8
CVE-2024-6459

The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the tem

10.0
CVE-2024-6500

The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion

9.8
CVE-2024-43042

Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

9.8
CVE-2024-42850

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity

9.8
CVE-2024-42639

H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as roo

9.8
CVE-2024-42638

H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started