72crm 9.0 has an Arbitrary file upload vulnerability.
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating sy
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre
Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially craft
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the sear
Bluecms 1.6 has SQL injection in line 132 of admin/area.php
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server w
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without auth
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA100
The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authentic
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnera
HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelini
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit
A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master co
A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by inje
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrn
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify whic
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source r
Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration u
Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack
A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modificati
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack wh
jizhicms v2.3.1 has SQL injection in the background.
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to t
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code e
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attacker
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain adminis
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated u
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librar
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staf
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staf
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /studen
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /libra
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started