libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address re
Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alar
Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that all
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized a
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers t
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be
JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the dev
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware uplo
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the u
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cann
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.ph
MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbi
An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfie
Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Defa
RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC
JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier
Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a W
A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of th
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix data race on CQP request done KCSA
In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: double free xprt_ctxt while still in use W
In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential oops in cifs_oplock_break With
In the Linux kernel, the following vulnerability has been resolved: net: macb: fix a memory corruption in extended buff
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix potential panic dues to unprotected sm
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix invalid buffer access for legac
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsit: Free cmds before session free
DVP-12SE11T - Out-of-bound memory write Vulnerability
DVP-12SE11T - Password Protection Bypass
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder a
Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Ser
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSR
A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13.
Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary argume
Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-short
An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA comp
A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with spec
A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof”
File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remot
WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any lo
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been ident
FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random n
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started