eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after
The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi
The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7
The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension
Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.
A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through
Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web app
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The se
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus expose
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workf
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu
OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by m
Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote atta
FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwritin
Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code b
emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadat
Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maxim
navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulne
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using de
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly han
webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable
newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not inco
newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisi
CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl
Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges
Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E
The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in th
The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having a
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18
Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access contro
set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability e
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vu
Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code duri
Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attac
Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execut
Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structur
Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by ov
ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configu
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces
An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers t
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started