A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.
The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV fi
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which c
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration fo
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or pe
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HT
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-
Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
Carel Boss Mini 1.5.0 has Improper Access Control.
drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request.
D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with t
webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network
Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation.
An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfigur
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthentica
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the appli
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is pos
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of speci
An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system com
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username pa
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/i
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sop
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deseriali
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows at
Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker,
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started