Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19)
Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without
Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15)
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with
Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registere
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated wi
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote atta
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w
A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr
In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB
@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching m
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain con
UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The func
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp
Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debu
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configu
Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromi
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbit
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compr
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromis
Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compro
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote at
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who
Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker
Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had com
Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere
Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh
Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a
Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the render
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started