The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthent
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using
iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 thro
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attacker
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticat
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad
The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can le
An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_2012110
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmw
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows
A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foregroun
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading t
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for
An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the
Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login por
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versi
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Mast
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser
PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto
PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an atta
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafte
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cac
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthen
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started