The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authent
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gate
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXE
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with t
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access b
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated user
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default Cr
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adj
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in th
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper co
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnera
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for C
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-se
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0,
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allow
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Public-only repository tokens can update private PR head branches
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Privilege Escalation via Access Token Scope Escalation in API
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-202
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch an
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion beca
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served t
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started