In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation
Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue aff
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker
An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw
EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password"
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows u
Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg
ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attacker
Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent nod
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in Open
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vuln
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file conta
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unau
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits i
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expres
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` re
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` pas
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` deref
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juni
Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vu
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI f
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote a
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalys
Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection
Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connec
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un
Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14
The administrative credentials can be extracted through application API responses, mobile application reverse engineerin
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Gene
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API
A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the hos
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started