Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without
The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is b
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL state
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile da
The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Sto
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function
Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtuse
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered i
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component
School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter
ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id par
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate paramete
A buffer overflow vulnerability exists in the razermouse driver of OpenRazer up to version v3.3.0 allows attackers to ca
A buffer overflow vulnerability exists in the razeraccessory driver of OpenRazer up to version v3.3.0 allows attackers t
A buffer overflow vulnerability exists in the razerkbd driver of OpenRazer up to version v3.3.0 allows attackers to caus
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POS
Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id param
Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Acti
Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via t
Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.ph
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.
The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not
A malicious attacker could exploit the interface of the Fieldcomm Group HART-IP (release 1.0.0.0) by constructing messag
A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafte
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can ea
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated
Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-aft
Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 b
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 throu
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configu
The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(
Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for
An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payl
A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE ha
The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrar
In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started