Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio exertio allows Object Injection.This issue affe
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG m
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S
Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCom
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Sh
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Se
The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to
Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attack
Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. Th
myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remot
An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default an
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden
An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginA
An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health
In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through fo
Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (R
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio
Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated re
A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the co
The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a net
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deser
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not pro
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12,
Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of th
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing un
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.
Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from t
Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started