A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote at
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A sp
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via ins
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows S
Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to e
Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue i
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTim
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function for
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrar
An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack G
An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack G
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an
School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username paramet
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdr
Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edi
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code v
Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the
Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2
An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on t
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/Ad
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.
In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathna
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an u
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started