The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_
The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up
The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers
The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_ver
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed
External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Com
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptca
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin pa
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only li
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject a
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inj
An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting t
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Managem
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image uplo
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnera
The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insuffi
The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attrib
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perf
New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from exte
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotel
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to th
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forger
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote com
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privil
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
GDidees CMS <= v3.9.1 has a file upload vulnerability.
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to
sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses
Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native
An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allow
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started