Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 a
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote fo
Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Bus
White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under th
Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password h
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an applicatio
Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full com
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single s
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct
Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.
io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-mu
A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed t
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with netwo
Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTM
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
PowerJob V4.3.2 has unauthorized interface that causes remote code execution.
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading t
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmwar
Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.
Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate priv
Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges.
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution wi
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the rend
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versio
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered us
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary comma
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request coul
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative
Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed f
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started