In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: call _ntfs_bad_inode() when failing to re
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decouple req recycling from RPC completio
In the Linux kernel, the following vulnerability has been resolved: nfs: use nfsi->rwsem to protect traversal of the fi
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix bcall rep leak and unbounded peek rp
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix dev use-after-free in xfrm async resumpti
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix xfrm state cache insertion race The xfrm
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: fix and simplify IP6IP6 tunne
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Don't use test_bit() in lockless
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix type confusion of dst_entry IOAM u
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of conn->preauth_info in
In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main t
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: Validate iph->ihl in nf_flow_
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_UNUSED pte bit The
In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on g
In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro
In the Linux kernel, the following vulnerability has been resolved: net: enetc: check the number of BDs needed for xdp_
In the Linux kernel, the following vulnerability has been resolved: sctp: add INIT verification after cookie unpacking
In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: don't cache shinfo across skb realloc
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of fp->owner.name in dura
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_create_write_req() to handle async
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix barriering when walking subrequest list
In the Linux kernel, the following vulnerability has been resolved: gue: validate REMCSUM private option length GUE pr
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6tables: mark malformed IPv6 extension
In the Linux kernel, the following vulnerability has been resolved: qede: fix off-by-one in BD ring consumption on buil
In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR
In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in igmp_gq_start_time
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix potential UAF in MLD delayed work
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catchall element handlin
In the Linux kernel, the following vulnerability has been resolved: ipvs: ensure inner headers in ICMP errors are in he
In the Linux kernel, the following vulnerability has been resolved: cifs: validate DFS referral string offsets parse_d
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: pin upper rpc_clnt across the TLS connect_w
In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dumps in enqueue tracep
In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be pullable in ife_de
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix unlikely race in try_get_locked_pte(
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrupt aff
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when mapping
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injecting
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't norm
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: reload possible stale data p
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: use dst in this direction whe
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: support IPIP tunnel with dire
In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MS
In the Linux kernel, the following vulnerability has been resolved: batman-adv: access unicast_ttvn skb->data only afte
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: prevent TVLV OOB check overflow A
In the Linux kernel, the following vulnerability has been resolved: sunrpc: pin svc_xprt across the asynchronous TLS ha
In the Linux kernel, the following vulnerability has been resolved: sunrpc: wait for in-flight TLS handshake callback w
In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rq_procinfo lifecycle to prevent dou
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_bvec() stores before
In the Linux kernel, the following vulnerability has been resolved: ntfs: grow index root value before reparent header
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started