Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword param
CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_i
Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining t
Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining th
Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining th
Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detect
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by ob
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter
On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend ser
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all pron
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These miss
A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in r
A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote c
SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute ar
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the
Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attac
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormL
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
D-Link - CWE-294: Authentication Bypass by Capture-replay
D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.
D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attac
The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check
calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allo
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an
1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of t
The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. T
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started