The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerab
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanis
An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection,
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an
An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.c
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service d
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SE
In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a neve
In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions So
In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpec
In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN
In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_lock
In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from prima
In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via miss
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant
In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal
In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer re
In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When c
In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boun
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last
In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom
In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroo
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extr
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the Namespace
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Ent
A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulne
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability fo
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CR
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-ena
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi
TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 14,853 CVE records rated CRITICAL in our database. Of these, 68 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started