An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in e
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.
Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() rea
Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, se
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircar
SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile A
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with t
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on com
XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can ex
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can ex
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiM
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability m
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x befor
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on com
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on com
XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author
XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systemat
XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTM
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two di
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an
An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMulti
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15,
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affect
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter i
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogE
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parame
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parame
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command paramet
Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication
Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication B
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML User
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur und
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started