Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter
vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for prod
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute
A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attac
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Coll
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. S
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notifi
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a sp
Controller DoS due to stack overflow when decoding a message from the server. See Honeywell Security Notification for
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific con
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Flor
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik all
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks lead
Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location no
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to e
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data.
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS:
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This coul
In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused dep
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users
The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
Online Piggery Management System 1.0 is vulnerable to SQL Injection.
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by
Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products,
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not
Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: be
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an a
Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dash
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started