Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by
Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's
3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an admi
OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary
Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fi
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-auth
EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water dis
Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critic
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtain
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.val
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer S
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA
Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to p
Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory change
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-
html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries thro
A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurity
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
Azure Front Door Elevation of Privilege Vulnerability
In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to l
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin in
10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the Mem
Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attacker
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to e
B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Str
Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the pin
Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attacker
Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to ex
Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the sa
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not valid
JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to ver
IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary c
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardc
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a byp
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT)
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allo
n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git nod
n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file ac
n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with per
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started