Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerabi
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulner
The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vul
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML E
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL s
ALCASAR before 3.6.1 allows still_connected.php remote code execution.
ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.
ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and in
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed
naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affec
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user do
Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PH
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring
SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including acces
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due
parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. T
Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authen
An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an
Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to laun
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited all
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow uninten
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that w
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an asserti
A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSort
OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and e
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an admin
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_compo
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and
Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu
Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Direc
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to e
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora F
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started