In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid l
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate priv
A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users
TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure han
SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL comm
Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affe
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated at
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Sta
An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via t
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prio
Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provi
SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges
SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges
A potential vulnerability has been identified in OpenText ArcSight Platform. The vulnerability could be remotely exploit
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible
The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corrupt
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corrupt
SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileg
SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the ad
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: fr
An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malici
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that w
An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in
An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstnam
RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, a
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeov
File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated us
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
CWE-287: Improper Authentication may allow Authentication Bypass
FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of Fi
Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.
The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, wh
In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the
Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute
Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository
Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through
The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compro
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started