MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulne
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leav
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursor
HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized co
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer over
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer over
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, an
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer over
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_plan
A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/set
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 thro
Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy tha
The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B
The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affe
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to r
WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p
Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all
Delta Electronics DIAView has multiple vulnerabilities.
Delta Electronics DIAView has multiple vulnerabilities.
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys
Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allo
Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an at
Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may
Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an
Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may all
Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may all
Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may al
GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configurat
Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to mani
NoteBurner 2.35 contains a buffer overflow vulnerability in the license code input field that allows attackers to crash
Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attack
Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote cod
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitizati
A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint tha
Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The a
Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane
RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt
Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests
File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng
ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started