Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create m
In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service.
SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName param
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName param
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname param
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the functio
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor an
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versi
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to version
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary co
Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine
Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine c
Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine co
An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preaut
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sen
A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially craft
An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Pyth
An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in t
Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnera
Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vul
Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerabili
Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cau
Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of t
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorize
Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel
Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.
"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability an
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vu
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vu
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary c
An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, ex
An issue in Jerrscript- project Jerryscrip v. 2.3.0 allows a remote attacker to execute arbitrary code via the ecma_buil
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects A
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to acc
A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es
A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Exec
SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started