The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.
Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedSt
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the f
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServl
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a v
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface.
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devNam
Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpaps
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the sam
capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalati
A SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensit
Usedesk before 1.7.57 allows chat template injection.
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose"
scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Medart Health Serv
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veribilim Software
There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability b
A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds
A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bou
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Bu
In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can pe
In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `canc
The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. T
The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Serv
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DRD Fleet Leasing
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can resul
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file wit
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrer
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system command
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an
Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any use
When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK
TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtere
An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jw
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a c
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to exec
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not esca
The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statem
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX actio
The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database b
The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents a
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could
Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system
Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml htt
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started