In the Linux kernel, the following vulnerability has been resolved: NFSD: Protect against send buffer overflow in NFSv2
The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20
The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20
The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59
A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of th
Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remo
A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the compon
Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenti
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, t
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo
File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filteri
Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use th
NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i
Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthentic
Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerabilit
AIRI is a self-hosted, artificial intelligence based Grok Companion. In v0.7.2-beta.2 in the `packages/stage-ui/src/comp
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sen
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i
Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema
Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.
An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t
The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior
DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering compo
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A r
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attac
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/a
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in
CWE-1392: Use of Default Credentials
CWE-1242: Inclusion of Undocumented Features
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started