In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after
In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode
In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pe
In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in x25_kill_by_neigh()
In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked sk
In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in chec
In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to prevent
In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow
In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in t
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networ
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_c
A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to acce
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker
An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute a
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary
An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, crea
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to d
An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated rem
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-tab
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to aut
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgra
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. U
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade
SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to v
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. Thi
The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its ac
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQ
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing u
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthen
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf
The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenti
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function tha
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function t
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that al
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that al
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol functi
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function t
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface th
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vu
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vu
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started