A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui ap
In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation o
In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local
The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Sto
In the Linux kernel, the following vulnerability has been resolved: btrfs: always detect conflicting inodes when loggin
Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection mid
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers
Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a
10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR,
Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbit
NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attac
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starti
Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI
aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com
In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio
An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw
A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated a
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary
BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attacker
Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execu
Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary
BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Han
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all suppor
Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged us
`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar co
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS)
A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th
Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service c
Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user
Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process th
YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-
Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers t
10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows rem
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Vers
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started