In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the functio
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_set
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_sta
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution fr
PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to ac
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulne
There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause maliciou
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerabi
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerabi
There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injec
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause maliciou
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause maliciou
There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1,
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t
A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file throu
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice comma
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR paramet
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. Thi
TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" functio
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerab
TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. Th
TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function.
TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" functio
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" functi
TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" functi
TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" functio
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started