A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code vi
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_co
An integer overflow in WhatsApp could result in remote code execution in an established video call.
Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine wa
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 a
Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScr
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p
Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger build
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML extern
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in
The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticate
Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injecti
md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE:
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /S
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_user
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monter
A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 a
SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.
SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via t
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege es
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload maliciou
Final CMS 5.1.0 is vulnerable to SQL Injection.
Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute a
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budg
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allo
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of servi
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_acce
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all
A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow
A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the prod
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-utility for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par
The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-mpeg for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-asns for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started