A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this co
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an at
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted
Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability th
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, a
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, un
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filt
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insec
OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attac
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModul
SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system r
An attacker can overwrite any file on the server hosting MLflow without any authentication.
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import f
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated a
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obta
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafte
SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class.
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.
An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute
Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are n
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design fo
ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogMo
A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated
There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated rem
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e
VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentia
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 acces
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM versi
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in ma
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with admini
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started