Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flas
A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/pos
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to X
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that cou
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that cou
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in a
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in vie
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the
Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator cla
Windows Network File System Remote Code Execution Vulnerability
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' acces
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Ci
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Ho
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injec
The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the mode
Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could le
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remo
An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, informa
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patien
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP fi
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_
Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.
An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a cr
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started