Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 20/432
9.8
CVE-2026-12949

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authent

9.6
CVE-2026-73843

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gate

9.0
CVE-2026-73842

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal

10.0
CVE-2026-72851

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXE

9.1
CVE-2026-72850

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with t

9.9
CVE-2026-72842

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access b

9.9
CVE-2026-72841

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated user

9.8
CVE-2026-72839

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default Cr

9.8
CVE-2026-72776

AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adj

9.6
CVE-2026-8715

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in th

9.1
CVE-2026-19297

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

9.8
CVE-2026-17482

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper co

9.9
CVE-2026-73656

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1

9.8
CVE-2026-19747

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to

9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnera

9.4
CVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider

9.8
CVE-2026-73649

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for C

9.6
CVE-2026-73644

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-se

9.1
CVE-2026-73567

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0,

9.8
CVE-2026-67614

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allow

9.1
CVE-2026-58508

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

9.1
CVE-2026-58443

Public-only repository tokens can update private PR head branches

9.1
CVE-2026-58433

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

9.1
CVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

9.8
CVE-2026-56654

Privilege Escalation via Access Token Scope Escalation in API

9.6
CVE-2026-56443

Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-202

9.1
CVE-2026-55982

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

9.1
CVE-2026-13051

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch an

9.1
CVE-2022-4993

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion beca

9.8
CVE-2026-73533

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served

9.8
CVE-2026-73532

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served t

9.1
CVE-2026-53791

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to

9.8
CVE-2026-66691

Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.

9.3
CVE-2026-66478

Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.

9.3
CVE-2026-66472

Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.

9.8
CVE-2026-66465

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

9.3
CVE-2026-66458

Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.

9.8
CVE-2026-66453

Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.

9.3
CVE-2026-66446

Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.

9.3
CVE-2026-66436

Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.

9.8
CVE-2026-66424

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

9.3
CVE-2026-61969

Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

9.8
CVE-2026-61967

Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.

9.3
CVE-2026-61966

Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.

10.0
CVE-2026-61962

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

9.8
CVE-2026-28185

Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.

9.8
CVE-2026-28149

Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.

9.8
CVE-2026-28148

Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.

9.3
CVE-2026-28142

Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.

9.8
CVE-2026-28008

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started