In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated us
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using i
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occ
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to sto
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) expos
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users wit
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vuln
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allo
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 all
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server bef
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogi
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP
OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s
microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (
nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa
IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started