On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By p
In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.
nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands
The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter)
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022
Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injectio
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye
A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker wi
api/views/user.py in LibrePhotos before e19e539 has incorrect access control.
Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC ap
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to a
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752,
Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=displa
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared
Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.
There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnera
KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resul
CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTML
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulne
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered
In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth
Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.
Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerabil
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this
The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL
The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a
The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using th
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started