Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows a
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() metho
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulner
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated
SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allo
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD
Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an a
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo
mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho
mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f
Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-i
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe
The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Re
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started