OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially per
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially per
Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially p
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker
Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentiall
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perfor
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functiona
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injecti
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started