In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download data
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated
FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co.
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function st
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silent
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Pyth
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugi
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. A
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles fr
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed,
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file ass
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authenticatio
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_ur
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/fo
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /gofor
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused T
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code t
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability i
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl a
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauth
The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it acce
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the functio
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to s
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stor
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basi
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to ex
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endp
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Ho
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started