Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requ
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL
TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality.
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_re
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-M
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbit
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the ne
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started