Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate pri
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate p
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunn
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shop
Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/c
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML respon
The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was i
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does n
drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request.
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass paramete
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port paramete
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient valid
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returni
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an aut
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the r
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and M
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host
iTerm2 before 3.4.18 mishandles a DECRQSS response.
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Admi
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injec
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in A
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemo
Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to
A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via spe
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started