Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Rem
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption a
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is al
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerab
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio
An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini
DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click r
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX F
A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create
screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue.
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Sco
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If clie
In the Linux kernel, the following vulnerability has been resolved: x86/sev: Evict cache lines during SNP memory valida
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed b
Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac param
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through
Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publi
aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that
aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that
Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsu
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab
In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote esc
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds read in smb2_sess_setup k
In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This p
In the Linux kernel, the following vulnerability has been resolved: mptcp: plug races between subflow fail and subflow
In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_brea
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42
A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum
The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and im
The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could a
A use-after-free vulnerability exists in the coap_delete_pdu_lkd function within coap_pdu.c of the libcoap library. This
A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘developme
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in e
An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF wp
Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started