Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwa
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated,
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP ma
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public cl
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.ph
Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in fi
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is
Arbitrary file upload vulnerability in php uploader
SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.
A limited SQL injection risk was identified in the "browse list of users" site administration page.
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the t
isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior,
SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/download
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to ar
BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordRe
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authTo
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitt
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929
Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.
Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vul
Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows fo
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any
Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special c
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.
Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability wh
SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application logi
Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started