A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipula
Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Inf
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 154
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated
Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attack
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a ma
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information T
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an esc
The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the
The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. T
Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol ca
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privil
JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in t
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at
Azure Entra ID Elevation of Privilege Vulnerability
Azure Entra ID Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthor
Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, al
Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, u
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arb
BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to
Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due
The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeo
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file
The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, Wri
The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all version
A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeE
A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset o
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi
An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before
A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0.
In the Linux kernel, the following vulnerability has been resolved: fs: dlm: fix use after free in midcomms commit Whi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthc
A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to in
Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/b
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started