The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Bud
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag
An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, up
Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from
A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Us
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthent
Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.
A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Ex
Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encryp
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authentic
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NV
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /a
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnera
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in
Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Pri
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Po
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac
An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis
SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerabili
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, p
OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze,
CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t
The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action,
oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.
Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at
Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual as
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exis
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerabil
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started