A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute a
IO FinNet tss-lib before 2.0.0 allows a collision of hash values.
Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/do
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Proje
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A
A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branc
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A spe
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firef
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while refere
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs s
Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firef
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed
Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affec
Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported m
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs presen
A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially ex
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerabi
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bug
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scri
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iO
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability aff
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, a
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulne
AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session comp
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allo
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not saniti
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the
Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request
The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the We
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause sys
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause syst
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause sys
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause syst
The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memor
Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteF
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started