The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t
The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t
The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a
The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t
The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory mana
The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more out
A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters.
Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account t
A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) pa
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, cou
A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c
An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1
A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on a
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder AP
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicio
Wedding Planner v1.0 is vulnerable to arbitrary code execution.
Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface
Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.p
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sendi
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg fu
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" funct
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started