A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented Deserializati
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an
The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2
In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompress
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could
A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote auth
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild i
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the buil
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using M
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthentica
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi
Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesa
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authori
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables de
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes
The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including,
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA syst
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on t
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at
An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7.
An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remo
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remot
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated
The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileg
scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parame
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the c
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thun
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started