Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classe
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classe
Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchas
Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, an
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?opera
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't prope
In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure.
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and l
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code exec
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code hig
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress n
On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `gi
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress al
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application d
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using i
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL inject
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacke
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and i
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value o
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.
Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vu
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unaut
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provid
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started