XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-mileston
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wi
CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Us
Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP G
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The
Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye:
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighb
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sendin
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sendin
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sendin
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sendin
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sendin
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the H
Unauthenticated server side request forgery in HPE Serviceguard Manager
Pre-auth memory corruption in HPE Serviceguard
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy.
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. Thi
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerabil
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A rem
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5.
Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful explo
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful explo
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attac
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command inj
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInt
Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the usernam
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, wh
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated
Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and T
Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create exten
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and An
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a cr
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a craf
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started