TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder
All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitiz
All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of inpu
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability v
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin,
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, h
D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin,
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a differ
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob"
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admi
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via Reade
Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To explo
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/hi
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ch
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attac
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function for
Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id paramet
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSe
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPP
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started