Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deplo
MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certai
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newp
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800,
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to
The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima
A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to c
A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based atta
The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and w
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to d
The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Con
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.
DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add free_transport ops in ksmbd connection
The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docus
Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-comm
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate
In the Linux kernel, the following vulnerability has been resolved: bnxt: properly flush XDP redirect lists We encount
The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086)
An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 -
The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover
A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the functio
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of
The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerab
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lea
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of i
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a
Cryptographic issue occurs due to use of insecure connection method while downloading.
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacke
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacke
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacke
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacke
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacke
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacke
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacke
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint tha
An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started