Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and
llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor()
Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, D
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module u
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unau
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to exe
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows a
TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at
A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the inter
The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant
Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the
Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromi
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Ex
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in a
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection vi
The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message s
An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critic
An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite
An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to o
An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwri
An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critica
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio
wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-boun
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical in
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e
Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and rub
act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processe
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in t
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started