In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list
In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use
In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received
In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADE
In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table
In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQ
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request pa
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI t
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filte
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell render
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scrip
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request va
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,
Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that resul
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.
Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per
Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per
concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock doe
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmg
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-fre
In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_l
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qual
In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The cod
In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regi
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durab
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching sad
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_ms
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() er
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strto
In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_st
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdm
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attacke
Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-
Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are e
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender va
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started