TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The expl
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long us
Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could
Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local a
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote atta
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerabili
Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme
Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty C
Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme
Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volt
Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execut
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to exec
Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Vol
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS c
An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS co
An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS c
An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to
An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulner
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privile
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component di
An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.m
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the W
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Manage
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manage
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the
Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attack
In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote e
The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the
Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact
A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings.
TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are se
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent un
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent
The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfilter
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started