A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allo
By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulner
A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown par
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized file
A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this iss
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubati
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially
jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentica
An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to
A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash an
An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially
A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or oth
An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their alloc
An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially res
Azure Portal Elevation of Privilege Vulnerability
Azure OpenAI Elevation of Privilege Vulnerability
ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not som
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in a
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the tx
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in fun
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the user
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or c
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shel
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer
CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous file
The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and in
react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/wo
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbit
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly v
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead
An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowe
pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there i
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass
Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead o
IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 throu
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versi
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execut
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with a
The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifical
Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A mali
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started