In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stre
In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations Add
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delt
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release and
In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segmen
In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-frag skb on DMA map
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare ClientGUIDs ClientG
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling befo
In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error cleanup If an erro
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link grou
In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port
In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free in vector_mmsg_rx()
In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_list skbs before running XDP A
In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircui
In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit pat
In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_shortci
DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the outp
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up t
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down s
In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with s
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB message onto the pen
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_challenge() Fix rxgk_
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrpc_recvmsg() Fix a
In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cancel the preallocation
In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_pr
In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_queue ordered In a
In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_failure when state
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow in immediate data l
In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix flex array size in struct nvme_
In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read_slot when reusing r10bio for
In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds check The fdpcidx bou
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink target during inode re
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix endpoint/socket association handling
In the Linux kernel, the following vulnerability has been resolved: lockd: Avoid hashing uninitialized bytes in nlm4svc
In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubufs only once vhost
In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrup
In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded address parameter length s
In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup using wr
In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong lo
In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP head-grow The xdp.
In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags before force-closing a
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_codel: Do not call qdisc_tree_reduce
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reporte
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if the ioremap fails
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated requests to allocate W
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Replace waitqueue and flag with complet
In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueue_to_
In the Linux kernel, the following vulnerability has been resolved: net/9p: fix race condition on rdma->state in trans_
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started