SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depe
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V dep
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may all
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special eleme
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to by
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id pa
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function
The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig tem
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper valid
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.
Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabl
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecur
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/f
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity func
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/fo
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to ga
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacke
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration u
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the bac
Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeho
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This
Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection
Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is
A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated att
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac
@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerabilit
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-
Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-
A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started