Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. T
Windows IIS Server Elevation of Privilege Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
In PicoTCP 1.7.0, TCP ISNs are improperly random.
In Contiki 4.5, TCP ISNs are improperly random.
In FNET 4.6.3, TCP ISNs are improperly random.
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vuln
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vuln
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker
A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SO
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug su
hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.
Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the d
langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-202
HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS)
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adv
A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled,
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.
PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, a
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.
SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and b
Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disab
Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component d
Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCata
Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote un
Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credent
IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Re
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauth
Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received fr
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary c
Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to co
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the trans
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected de
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started