An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have be
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unau
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attacke
A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vu
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by u
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privile
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXML
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code executio
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.759
Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac paramete
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI componen
D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,
Product: AndroidVersions: Android SoCAndroid ID: A-273754094
vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted requ
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenat
The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allo
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitr
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by sup
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change t
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a rem
File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to exe
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitr
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid cr
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitr
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code
LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This is
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are ru
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characte
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem
Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) whi
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started