An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sani
hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could
A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in sou
Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecate
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0
Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.
SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoin
Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability,
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability,
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.updat
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 202
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` ac
Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to versio
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting i
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC end
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c
Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jell
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formu
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its q
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder con
ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and exec
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrar
A vulnerability in the web application allows standard users to escalate their privileges to those of a super administra
In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI d
In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() i
In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits diff
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_gra
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor comp
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests'
The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the Clo
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may t
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe s
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays
Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overf
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started