Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 22/432
9.3
CVE-2026-66659

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome

9.8
CVE-2026-18391

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor

9.8
CVE-2026-18366

The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access

9.1
CVE-2026-16538

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top

9.8
CVE-2026-16051

The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re

9.8
CVE-2026-15039

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all

9.9
CVE-2026-72526

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man

9.6
CVE-2026-70398

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil

9.1
CVE-2026-68431

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requ

9.8
CVE-2026-68067

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active

9.1
CVE-2026-67568

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int

9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic

9.4
CVE-2026-66147

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier

9.9
CVE-2026-48765

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa

9.8
CVE-2026-73034

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f

9.6
CVE-2026-73032

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav

9.1
CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version

10.0
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit

9.8
CVE-2026-16230

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali

9.8
CVE-2026-73211

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat

9.3
CVE-2026-73090

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi

10.0
CVE-2026-71398

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

9.1
CVE-2026-71362

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att

9.8
CVE-2026-69102

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper

9.0
CVE-2026-48381

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL

9.6
CVE-2026-47705

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality.

10.0
CVE-2026-27302

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

9.6
CVE-2026-71384

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul

9.3
CVE-2026-70306

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before

9.8
CVE-2026-65791

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ

9.8
CVE-2026-62893

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-62878

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-62815

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-59124

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to

9.4
CVE-2026-50516

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el

10.0
CVE-2026-48362

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

9.8
CVE-2026-12571

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

9.3
CVE-2026-73080

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_re

9.1
CVE-2026-73069

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad

9.8
CVE-2026-72920

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s

10.0
CVE-2026-17061

A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2

9.8
CVE-2026-51584

An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S

10.0
CVE-2026-48056

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro

9.8
CVE-2026-46670

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp

9.1
CVE-2026-72748

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a

10.0
CVE-2026-58115

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In

9.6
CVE-2026-18972

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-M

9.9
CVE-2026-72603

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbit

9.8
CVE-2026-72599

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the ne

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started