Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 14/432
9.0
CVE-2026-75625

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to t

9.0
CVE-2026-75130

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions

9.3
CVE-2026-67921

Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and

9.9
CVE-2026-66780

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to jo

9.1
CVE-2026-52610

An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or

9.8
CVE-2026-52608

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitra

9.8
CVE-2021-43717

An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection

9.8
CVE-2021-43716

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector

9.8
CVE-2026-67271

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with r

9.1
CVE-2026-52723

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

9.1
CVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity

9.3
CVE-2026-75913

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the

9.3
CVE-2026-45118

MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or pro

9.8
CVE-2026-45117

MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape use

9.6
CVE-2026-12564

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugin

10.0
CVE-2026-75784

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of th

9.3
CVE-2026-74015

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

9.8
CVE-2026-73996

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

9.8
CVE-2026-73397

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

9.3
CVE-2026-73392

Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.

9.1
CVE-2026-73381

Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

9.8
CVE-2026-73380

Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

9.8
CVE-2026-73376

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

9.8
CVE-2026-73366

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

9.3
CVE-2026-73365

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

9.3
CVE-2026-73355

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

10.0
CVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

9.8
CVE-2026-73341

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

9.3
CVE-2026-73339

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

9.3
CVE-2026-73187

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

9.9
CVE-2026-66627

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.

9.8
CVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to

9.9
CVE-2026-32474

Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

9.8
CVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

9.9
CVE-2026-32463

Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

9.9
CVE-2026-32444

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

9.6
CVE-2026-28192

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

10.0
CVE-2026-75874

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

9.6
CVE-2026-75783

A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknow

9.8
CVE-2026-74990

Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of thes

9.8
CVE-2026-74989

Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another securit

9.8
CVE-2026-74988

Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corrupt

9.8
CVE-2026-74987

Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed eviden

9.1
CVE-2026-74986

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox

9.8
CVE-2026-74985

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.

9.8
CVE-2026-74979

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thun

9.8
CVE-2026-74964

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR

9.1
CVE-2026-74961

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154

9.1
CVE-2026-74959

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14,

9.1
CVE-2026-74956

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ES

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started