Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_
Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) was discovered to contain a stack overflow via the device
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0
Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow vi
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1
Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775)
Tenda 4G300 v1.01.42 was discovered to contain a stack overflow via the page parameter at /VirtualSer.
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_r
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to wr
social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION
PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0,
CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command i
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication,
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication pro
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its commu
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communicati
Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling at
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to sp
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for devi
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send email
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3,
The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike serv
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspa
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on th
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation
ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.ph
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arb
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a
ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/c
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the cate
SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a re
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started