Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*)
Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers a
Buffer overflow in mDNS NSEC record registering process of Office / Small Office Multifunction Printers and Laser Printe
Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*)
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to ex
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer ove
A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41. Affected is an unknown function of
Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an at
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension
XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attribu
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UA
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML docu
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to in
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other activ
A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of
Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attack
Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-b
Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, poten
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, a
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc
`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer,
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected devi
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administra
libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPD
`effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior t
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions start
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4,
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4,
This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. This iss
Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.
SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set.
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function set_tftp_upgrad.
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started