The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc
OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulne
The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i
NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subt
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel t
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re
Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via Jav
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to p
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privile
Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-au
PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteC
PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the brow
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the work
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the
The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authe
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable S
A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access t
A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device
An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a cra
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by
Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbit
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the funct
In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address.
Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to revea
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms duri
Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method return
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosR
A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the fil
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started