By using a specific credential string, an attacker with network access to the device’s web interface could circumvent th
A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A speci
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to
There is an object injection vulnerability in swfupload plugin for wordpress.
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimite
There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI351
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes
EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md"
The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cac
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applica
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's pas
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator coul
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leav
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachment
D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __aja
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 a
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.
The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerab
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no
Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient e
RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_
The Texercise package in PyPI v0.0.1 to v0.0.12 was discovered to contain a code execution backdoor. This vulnerability
The Rondolu-YT-Concate package in PyPI v0.1.0 was discovered to contain a code execution backdoor. This vulnerability al
The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attacker
The Catly-Translate package in PyPI v0.0.3 to v0.0.5 was discovered to contain a code execution backdoor. This vulnerabi
The Togglee package in PyPI version v0.0.8 was discovered to contain a code execution backdoor. This vulnerability allow
The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. Th
The Scoptrial package in PyPI version v0.0.5 was discovered to contain a code execution backdoor via the request package
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vu
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package.
The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request packag
The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request packa
The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vul
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request pack
The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. Th
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the requ
The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the reques
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started