Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent netw
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software In
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when Raise
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attack
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP
Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p
Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a
Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perfor
Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially
Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code i
Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a s
Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially p
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar f
Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might a
In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthent
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middlewa
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /a
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the che
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue a
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate t
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apac
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows
A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of th
WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers
WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate
WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbit
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open X
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific,
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started