Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.
Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had c
Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 co
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earli
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Win
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier,
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier,
Unauthorized access to Gateway user capabilities
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connection
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versio
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versio
A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER S
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting bot
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fl
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries a
btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witn
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows get
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 cl
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PD
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre
XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI
Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote un
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is pos
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing X
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbi
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettin
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewal
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagem
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWi
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWire
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started