In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can
Microsoft Exchange Server Remote Code Execution Vulnerability
HTTP Protocol Stack Remote Code Execution Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TI
cscms v4.1 allows for SQL injection via the "page_del" function.
cscms v4.1 allows for SQL injection via the "js_del" function.
PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py,
In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. S
In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search fu
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malic
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise an
Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key a
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python e
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentic
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulne
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and U
The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malic
There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this
There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may c
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the
Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the des
An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.p
Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipel
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp
uppy is vulnerable to Server-Side Request Forgery (SSRF)
A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the au
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when re
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path travers
The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerabilit
HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system inte
HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.
There is a Configuration defects in Smartphone.Successful exploitation of this vulnerability may elevate the MEID (IMEI)
There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel cras
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started