Azure CycleCloud Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be
An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets ac
Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicCon
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow
An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_aw
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p
A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions
The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This i
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CON
PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code e
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multip
SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.
The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker t
Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrar
An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows atta
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv
A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an
The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attacke
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitr
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers t
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitr
Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Up
Unrestricted Upload of File with Dangerous Type vulnerability in Dang Ngoc Binh Audio Record audio-record allows Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Sh
Unrestricted Upload of File with Dangerous Type vulnerability in HB WEBSOL HB AUDIO GALLERY hb-audio-gallery allows Uplo
Unrestricted Upload of File with Dangerous Type vulnerability in UjW0L Image Classify image-classify allows Upload a Web
Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesi
An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more tha
The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va
The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can l
The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to pr
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file re
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient
The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the db
The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started