Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the proces
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i
Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1
rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation
RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attacke
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthe
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and th
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions,
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remo
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session
exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto_
DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g.,
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_st
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privi
The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, al
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-b
In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STAT
In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by
In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid hea
In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys(
In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segment
In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being
In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP
In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic XDP fr
In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer in
In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its ti
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started