In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_s
In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflict
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 con
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.
In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This coul
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.
Elevation of Privilege
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass auth
phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the la
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Ex
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow.
In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired d
In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could le
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability co
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An at
A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3
rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path.
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that,
Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers t
In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring a
In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring add
In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffe
A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BAS
Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to
Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L
A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to exe
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allow
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 1
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attacker
A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11
WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was i
Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable
TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024
An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploi
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirec
TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read,
Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to
A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControl
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started