Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG p
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://pl
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extr
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed i
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or re
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both t
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere ext
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised
Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to p
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started