METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitr
Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install
EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application e
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0
Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade In
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform backgrou
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function modul
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authori
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication b
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allo
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vuln
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to m
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorizatio
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derive
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation en
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts serv
Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Info
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to rea
User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining
Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attack
An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can
GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-s
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OP
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including
macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workf
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied userna
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attacke
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code b
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started