The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third pa
The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third pa
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filter
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par
The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-urls for python 0.1.0, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using th
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation paramet
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' subst
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager P
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-c
Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnera
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability m
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerabili
Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the conf
Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will caus
The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability m
Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may caus
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may re
Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList
Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.
Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session to
Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivit
Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking
Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer ov
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer ov
There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started