Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field a
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov W
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alternativ
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Si
OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GF
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients conta
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubect
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling w
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an O
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_c
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pi
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacke
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authe
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions u
Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attacker
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attacker
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enabl
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exp
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n al
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including,
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started