A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass aut
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attacker
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additio
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for
Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to
The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affect
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File In
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in rea
Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scatte
Memory corruption in modem due to improper length check while copying into memory
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Mana
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /gofo
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /gof
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /gofo
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /gofo
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insuffic
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may af
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to e
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to d
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbi
Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and ch
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensiti
Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-l
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain acce
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation
In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalat
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started