Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authenticati
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authe
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.
This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteF
In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthent
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy p
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parame
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw paramete
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication,
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be
Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exp
ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authenticati
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Auth
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Auth
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authenticati
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authenticati
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authenticati
Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Att
A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege esc
The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentia
The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability ma
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023
Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address
DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP addres
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges vi
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a vali
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status se
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.
Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and P
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started