In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding new
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on su
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_ga
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The S
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter Th
In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count fo
In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text S
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: fix TSO segmentation explosion
In the Linux kernel, the following vulnerability has been resolved: igc: set tx buffer type for SMD frames Sashiko poi
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id fr
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file creation
In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdict sk_data_ready racing with k
In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN
In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bo
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix durable reconnect error path file lifeti
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensur
In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision f
In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in ip
In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb
In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel
In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_deco
In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference t
In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net namesp
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' E
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the act
In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_ju
In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-fr
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before
In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment add
In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms
In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent
In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_d
In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() W
In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error
In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfs
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifi
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segme
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be ab
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association a
PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsear
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/St
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started