Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi
The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to g
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi
Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry In
The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountai
In the Linux kernel, the following vulnerability has been resolved: libceph: fix invalid accesses to ceph_connection_v1
The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code executi
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vu
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Host
Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images custom-post-types-image allows Code
The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Te
The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service
Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared
AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access
Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This s
Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Ins
A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticket
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system
Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash
MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive Property
HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to addr
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configu
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior t
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.236
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticate
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads du
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged
The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker
Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standa
In the Linux kernel, the following vulnerability has been resolved: NFSD: Protect against send buffer overflow in NFSv2
In the Linux kernel, the following vulnerability has been resolved: nfsd: under NFSv4.1, fix double svc_xprt_put on rpc
In the Linux kernel, the following vulnerability has been resolved: net/smc: Reset connection when trying to use SMCRv2
CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In
A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file del
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticate
The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an a
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started