An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li
Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi
Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerabili
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dn
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Valid
Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound m
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Ke
Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeu
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-qu
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to buil
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validatio
The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pr
Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state w
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowin
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser
Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passe
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common lib
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffi
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub R
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t
ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_contr
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started