TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpMode
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptograp
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-c
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack b
An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of pri
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a seve
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.
An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by
SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPr
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any for
Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisio
ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canon
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you us
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achie
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restric
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared st
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have bee
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of t
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerabili
Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause o
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagV
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be execut
In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed w
In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an att
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron
Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbo
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability i
Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier coul
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, grant
A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earli
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) pro
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected r
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started