In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one in mapping pairs decoding boun
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate attribute values on lookup ntfs_att
In the Linux kernel, the following vulnerability has been resolved: ntfs: add bounds check before accessing EA entries
In the Linux kernel, the following vulnerability has been resolved: ntfs: not change 0-byte $DATA attribute to non-resi
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index block header more strictly Mo
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index entries on reading Validate i
In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN accumulator overflow
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident index root values on lookup
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth limit to indx_find_buffer to pr
In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move in indx_insert_into_root befor
In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split-point offset in indx_insert_i
In the Linux kernel, the following vulnerability has been resolved: ntfs: sanitize MFT references returned from ntfs_lo
In the Linux kernel, the following vulnerability has been resolved: ntfs: make system files immutable to prevent corrup
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_ma
In the Linux kernel, the following vulnerability has been resolved: tcp: defer md5sig_info kfree past RCU grace period
In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send erro
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvme
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offse
In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation
In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command inste
In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT TransportID parsing to t
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free i
In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_
In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by t
In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX frags for CPU MANA al
In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruption with header-split
In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial se
In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry size 64-bit in fil
In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_conn_ne
In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with an out-of-range payl
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong ipv6 transport off
In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __i
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper ne
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control o
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensit
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path t
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that a
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/document
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the serve
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vul
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without aut
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 th
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacke
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authentica
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backl
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started