The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Ove
AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to
The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an un
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Inject
Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anhvnit Woocommerc
Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issu
In the Linux kernel, the following vulnerability has been resolved: net: ena: Add validation for completion descriptors
In the Linux kernel, the following vulnerability has been resolved: tipc: force a dst refcount before doing decryption
In the Linux kernel, the following vulnerability has been resolved: gve: Clear napi->skb before dev_kfree_skb_any() gv
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: disable rx data ring on dma allocation fai
In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic in XDP_TX action In the XD
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when proc
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypa
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any fi
An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted m
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 p
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all
Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when pr
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any loc
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp
An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-f
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earl
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platfo
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.
SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Cod
SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows
Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After exec
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affec
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 1
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started