The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send
The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_f
The dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask sen
The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file functi
The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is
The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send
The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal becaus
The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask se
The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send
The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function
The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask
The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file fu
The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file f
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the F
The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file fun
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path tra
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file f
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file
The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file functi
The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask s
The BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file
The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file
The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_fi
The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send
The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_fi
The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file fu
The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file funct
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_fi
The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask se
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because
The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file fun
The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_fil
The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_f
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are sub
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in t
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorize
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoin
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client a
SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obt
TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in
Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter
Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauth
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started