GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflo
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflo
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overfl
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vul
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overfl
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root p
The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploi
The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may resu
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful
The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation
The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerabil
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploa
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to executio
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/in
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manag
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The s
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configura
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable
OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installat
Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5c
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatc
In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by
The d8s-file-system package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by
The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by
The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thi
The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted b
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started