nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the ema
Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` met
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for
In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al
The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command
Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbit
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated att
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI ins
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to system
Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to tr
SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/
Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users n
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via
thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulner
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o
EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_tra
EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup cop
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authentica
plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the pac
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Sess
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's un
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names
An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the o
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated use
Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress Publi
Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-download
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder all
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web S
Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious
Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalati
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started