Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Pro
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop P
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google
Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affect
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash t
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Softw
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Te
Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, al
File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attack
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious pr
An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.
Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Par
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malici
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request pa
hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution back
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to co
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServ
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via u
GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filte
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a fac
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.
SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student
SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file,
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Check
versionn, software for changing version information across multiple files, has a command injection vulnerability in all
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.
Liima before 1.17.28 allows server-side template injection.
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/Gala
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_de
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vuln
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker t
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started