In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap bro
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Disc
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds a
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prep
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk siz
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREA
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computa
The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credential
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA ba
In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_inser
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the sys
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a netwo
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authent
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Acti
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the p
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated att
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem
Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive Id
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its datab
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started