An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary
The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,
PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that c
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous T
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to aut
@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to ar
MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to se
MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root passwor
Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configura
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remo
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file a
Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrati
An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrad
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwo
CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Ver
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vuln
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and includin
Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's c
Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal
In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twi
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140
Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thund
An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method
A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDel
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UN
Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery. This
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix QP destroy to wait for all references
DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable
In the Linux kernel, the following vulnerability has been resolved: cifs: fix session state check in reconnect to avoid
A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to rec
NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not va
SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management Sy
In multiple locations, there is a possible way to launch an application from the background due to a precondition check
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php comp
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary comm
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user acco
In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The en
In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential use-after-free bugs in TCP_Serv
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_i
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started