Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 10/432
9.6
CVE-2026-16835

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9

9.6
CVE-2026-16687

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9

9.3
CVE-2026-66794

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows

9.0
CVE-2026-32475

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.

9.8
CVE-2026-75143

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). libris

9.0
CVE-2026-72530 KEV

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4

9.8
CVE-2026-72529 KEV

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4

9.1
CVE-2026-71470

A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource

9.1
CVE-2026-49441

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 an

9.1
CVE-2026-48162

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an

9.1
CVE-2026-48024

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an

9.9
CVE-2026-20359

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

10.0
CVE-2026-20358

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

10.0
CVE-2026-20357

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

9.6
CVE-2026-20318

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

10.0
CVE-2026-20317

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

10.0
CVE-2026-20315

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

9.9
CVE-2026-20231

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

10.0
CVE-2026-20030

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

9.1
CVE-2026-71960

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosqui

9.8
CVE-2026-53451

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.

9.8
CVE-2026-52889

Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults

9.3
CVE-2026-47187

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can retu

9.9
CVE-2026-16816

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands

9.8
CVE-2026-16656

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper auth

9.9
CVE-2026-15068

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary comma

9.1
CVE-2026-15065

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to t

9.9
CVE-2026-51366

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary c

9.8
CVE-2026-16019

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation

9.3
CVE-2026-73391

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

9.8
CVE-2026-73390

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

9.8
CVE-2026-73389

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

9.3
CVE-2026-73388

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

9.8
CVE-2026-73364

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

9.8
CVE-2026-73347

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

9.3
CVE-2026-73185

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

9.3
CVE-2026-73183

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

9.8
CVE-2026-66613

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

9.8
CVE-2026-72889

Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves

9.8
CVE-2026-58082

The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some

9.8
CVE-2026-58081

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied outp

9.0
CVE-2026-18937

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input o

9.8
CVE-2026-18776

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, all

10.0
CVE-2026-18051

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil

9.8
CVE-2026-18031

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session

10.0
CVE-2026-76008

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-

9.9
CVE-2026-76004

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability

9.9
CVE-2026-76003

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /gofo

9.9
CVE-2026-75976

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wa

9.6
CVE-2026-76036

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started