SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer ove
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper pr
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format st
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-bas
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlle
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the abi
A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controll
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-con
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where th
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from o
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can sen
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/au
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attacker
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Bayla
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery.
Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started