Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

6,448
Total
68
Known Exploited
Showing 6,448 of 6,448 total · Page 2/129
9.1
CVE-2026-80603

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by

9.8
CVE-2026-80600

In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after s

9.8
CVE-2026-78032

SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with

9.8
CVE-2026-76581

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,

9.0
CVE-2026-40541

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain

9.8
CVE-2026-82082

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje

9.1
CVE-2026-61800

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

9.8
CVE-2026-78239

Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote at

9.8
CVE-2026-76943

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp

9.8
CVE-2026-76179

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication

9.8
CVE-2026-75337

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The us

9.8
CVE-2026-73125

Ebyte device web management interface does not consistently enforce authentication before granting access to administra

9.8
CVE-2026-71187

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacke

9.8
CVE-2026-69658

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level atta

9.1
CVE-2026-50152

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2

9.8
CVE-2026-81934

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-d

9.8
CVE-2026-59313

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Ev

9.1
CVE-2026-59283

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable

9.8
CVE-2026-37006

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker

9.8
CVE-2026-19092

The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rend

10.0
CVE-2026-81735

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g

9.8
CVE-2026-81707

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inj

9.8
CVE-2026-81702

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al

9.8
CVE-2026-81701

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in

9.8
CVE-2026-81700

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that

9.1
CVE-2026-81098

The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc

10.0
CVE-2026-81096

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat

9.1
CVE-2026-81094

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked

9.1
CVE-2026-57499

Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log

9.3
CVE-2026-16279

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Releas

9.8
CVE-2026-74233

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242

9.8
CVE-2026-74232

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink

9.8
CVE-2026-78292

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

9.3
CVE-2026-78288

Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.

9.8
CVE-2026-78286

Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

9.1
CVE-2026-78274

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

9.3
CVE-2026-78260

Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

9.6
CVE-2026-59354

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registratio

9.8
CVE-2026-32566

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

9.3
CVE-2026-32479

Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

9.6
CVE-2026-77016

The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate prof

9.4
CVE-2026-59270

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative creden

9.8
CVE-2026-47892

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predi

9.8
CVE-2026-47891

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma

9.8
CVE-2026-47890

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fr

9.8
CVE-2026-47884

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping th

9.1
CVE-2026-75340

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is

9.8
CVE-2026-75338

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fet

9.8
CVE-2026-75336

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.

9.1
CVE-2026-75332

Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 6,448 CVE records rated CRITICAL in our database. Of these, 68 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started