An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8,
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Monterey 12.
The issue was addressed with improved memory handling. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available afte
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper st
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3
SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privilege
PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands o
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and th
Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the com
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "resto
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute c
Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology
GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web reque
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repa
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.818. During installation, binaries gets
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the obje
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentic
KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can becom
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and maste
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and maste
A use of uninitialized pointer vulnerability exists in the PQS format pFormat functionality of Open Babel 3.1.1 and mast
A use of uninitialized pointer vulnerability exists in the MSI format atom functionality of Open Babel 3.1.1 and master
An out-of-bounds write vulnerability exists in the PQS format coord_file functionality of Open Babel 3.1.1 and master co
A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master c
An out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit
vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect fun
Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclo
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started