PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-b
Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi
Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_
Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain uninte
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on net
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_est
In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths
In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buf
In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by referen
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode T
In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets
In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response
In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io
In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_s
In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret
In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_inv
In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion with
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.
Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.
Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the hap
A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration end
A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established wi
A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on th
A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be
A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be per
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypher
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perfo
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofin
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to exe
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerabil
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vuln
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.load
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_fi
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contai
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromi
Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the re
In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started