In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after s
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote at
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp
An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The us
Ebyte device web management interface does not consistently enforce authentication before granting access to administra
The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacke
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level atta
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-d
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Ev
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable
A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rend
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inj
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Releas
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registratio
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate prof
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative creden
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predi
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fr
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping th
The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is
disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fet
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 6,448 CVE records rated CRITICAL in our database. Of these, 68 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started