A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure tha
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encryp
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus
In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo VMs
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that co
In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) worki
In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiat
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Inf
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be r
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gai
In the Linux kernel, the following vulnerability has been resolved: tcp: do not accept ACK of bytes we never sent This
The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file u
The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowin
The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute
Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to cha
CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId param
Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D25
Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 a
A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allow
A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 all
A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System
A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 al
A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 all
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A speciall
The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow
A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality o
A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm.
Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB:
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing
Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the func
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/pr
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/gofo
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started