Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulne
libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IG
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supp
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the T
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files w
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as exe
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypas
calibre-web is vulnerable to Business Logic Errors
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel atta
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by P
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter func
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2
In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This co
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentic
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter
Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encodin
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /ap
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 cop
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34
The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which a
The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inje
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) a
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.2
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploi
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) i
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerab
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a m
Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon C
Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerabl
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started