Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys file_name_len integer overflow and resultant b
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys feature_name_len integer overflow and resultan
Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET
The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.
The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b
PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Pr
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able
XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.5 and iPadOS 16.5. A remote attacker
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, mac
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7.7, macOS
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted
Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server,
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) fro
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users lis
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitr
Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable}
laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave
Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo:
netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.ph
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugi
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started