Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrar
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network dr
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a netwo
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitr
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A ba
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 aut
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate
Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerabilit
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano,
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the Enc
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backen
The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletio
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started