The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker t
pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remo
A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brut
An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a c
ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential
A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary lo
A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file l
Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not inc
Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command in
Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the impro
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on
OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks
A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all
SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete d
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in t
The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.
The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin
Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Tech
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictabl
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Ex
In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was
The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl
The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_comp
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code exec
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized at
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on th
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exp
Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing aut
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presu
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caus
When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a passwo
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started