An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware v
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Cont
Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass
scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To
An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.p
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacke
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote c
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadAction
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from t
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure R
Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter
wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-
This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets user
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain com
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its Ultra
The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereb
Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A
In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. Th
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privile
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login c
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl p
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_use
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started