Improper Privilege Management vulnerability in xtemos Woodmart Core allows Privilege Escalation.This issue affects Woodm
Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez:
Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue a
Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects Watc
Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Pl
Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows
The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated
A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor
Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execut
Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allo
Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This
Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap.
SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacke
A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulne
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due
A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code exe
A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall
A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization
A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute ar
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside
CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could res
CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacke
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other servic
Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might resul
An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints
Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL c
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDB
There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated
There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated
There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthent
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that coul
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenti
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenti
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, reposito
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that w
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability a
SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote
Weak account password in GE HealthCare EchoPAC products
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects Pr
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an atta
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded pa
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started