An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could r
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attac
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The
The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authent
A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the f
Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStaticFiles in lib/middleware.c allows a stack-based bu
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that a
A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by
Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEnc
An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, t
app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication,
Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applicati
During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some att
The handler of the retrofit validation command doesn't properly check the boundaries when performing certain valida
The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This cou
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An un
Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerabi
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerab
ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. A
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are r
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 thro
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file
ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attack
ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated r
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka
A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12
A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the serv
Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/getting
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProCon
SQLi vulnerability in Starshop component for Joomla.
SQLi vulnerability in S5 Register module for Joomla.
SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and o
SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started