A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH
The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This
The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to
A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goform
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themi
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to
Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectiv
Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the dev
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to by
Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script t
The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers
The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below co
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP reques
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import modul
Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Fil
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Nat
Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary B
Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) a
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template in
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template in
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain a
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple cr
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cros
gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file
An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker
SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive informat
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate
Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecu
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started