Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand funct
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime f
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName
Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `
Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload wi
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom par
Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged r
Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an
Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain acce
Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain
A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and
The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura
Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analy
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible t
lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object dest
The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with u
The application was vulnerable to a session fixation that could be used hijack accounts.
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functio
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, w
The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messa
There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters u
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that c
There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper au
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters befor
xfig 3.2.7 is vulnerable to Buffer Overflow.
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/S
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th
Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacke
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrar
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_j
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th
The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC
Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Comman
Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands”
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadat
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebu
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started