Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction
Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an a
Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction
Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may a
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthen
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API reques
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coin
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local Fil
Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allo
SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution du
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TL
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in
Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwri
JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureAp
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain a
Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, cau
An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.
Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbit
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incomi
IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the sys
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authe
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled t
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy S
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for aut
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. I
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started