A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W21
In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after buffer
An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass au
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix double put of request If a netfs reques
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix a race between renames and directory log
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldu
The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web,
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated atta
A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and
A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVide
A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality o
A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar En
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin
The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima
The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located wit
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote att
An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full acces
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This
Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi
Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a
Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Informati
The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_inf
The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi
The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up
HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and be
Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulne
Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started