FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266
SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows a
jizhiCMS 2.5 suffers from a File upload vulnerability.
SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 all
SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arb
SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1
SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arb
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo fun
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVir
Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle fun
An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0
In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call finalize with bh disabled Wh
In the Linux kernel, the following vulnerability has been resolved: igc: avoid returning frame twice in XDP_REDIRECT W
In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() I
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Mak
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Suppo
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony E
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony E
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony E
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary c
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetun
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_g
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_g
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements mul
mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass
A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval func
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sendi
A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpo
lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signu
An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, al
A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository,
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify
iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they sho
Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthe
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna
The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to p
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr
A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, A
IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without suffi
SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability al
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started