Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user l
Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic k
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Ma
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output func
The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperRep
The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO J
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.
Unauthenticated remote arbitrary code execution
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versi
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database cre
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr
SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/repla
Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which c
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthe
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL state
The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before u
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer o
A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escal
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability m
Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape
cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6
Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker ca
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remo
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brut
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /
Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a
Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary comma
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started