A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal
A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allow
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This all
Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which
Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect A
Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management
Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows
PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that c
The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password ca
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7.
School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation
The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter
An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker t
Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forger
Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross S
Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin
Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the
WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the d
A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerabili
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R3
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized inp
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitra
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue aff
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary com
OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campai
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_cre
The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql que
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started