The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Mis
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before
Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This
Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Res
A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Managem
A missing protection against path traversal allows to access any file on the server.
The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the W
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These v
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknow
A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the
A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qos
A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments o
The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a f
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verificat
An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds write
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated re
A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remot
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affe
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could l
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
An authentication bypass vulnerability exists in HPE StoreOnce Software.
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain admini
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local
A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to
YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stockt
The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,
Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulner
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been id
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started