Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may
Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal sto
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Meteri
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /pu
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attac
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracke
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundan
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write p
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
Memory corruption due to double free in core while initializing the encryption key.
memory corruption in modem due to improper check while calculating size of serialized CoAP message
Memory corruption in modem due to improper input validation while handling the incoming CoAP message
Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of
Memory correction in modem due to buffer overwrite during coap connection
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate fi
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the compo
Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the uploa
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before ver
An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe
An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges v
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the servi
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - version
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - ver
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version
An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary
Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the langua
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16.
An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2
An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticate
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writ
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started