In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic
The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before usi
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which co
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could
The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_
The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated a
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitr
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. T
A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the user
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By man
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause san
Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnera
Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of th
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability m
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi v
An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sens
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate
SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute
An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1a
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows rem
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists becau
EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first fa
In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to i
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Swi
An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Mon
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uplo
EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started