Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 26/432
9.9
CVE-2026-48086

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

9.8
CVE-2026-48085

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

9.1
CVE-2026-3418

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti

9.6
CVE-2026-19175

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s

9.6
CVE-2026-19171

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially per

9.6
CVE-2026-19170

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially per

9.6
CVE-2026-19166

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially p

9.6
CVE-2026-19164

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker

9.6
CVE-2026-19157

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentiall

9.6
CVE-2026-19149

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perfor

9.3
CVE-2026-18367

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS

9.8
CVE-2026-17032

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo

9.8
CVE-2026-15734

A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att

9.8
CVE-2026-15733

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio

9.8
CVE-2026-15732

A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functiona

10.0
CVE-2026-14812

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator

10.0
CVE-2026-11976

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both

9.0
CVE-2025-14561

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o

9.8
CVE-2026-67261

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injecti

9.1
CVE-2026-66709

Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

10.0
CVE-2026-66665

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

9.8
CVE-2026-66662

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

9.3
CVE-2026-66447

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

9.8
CVE-2026-65581

Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

9.8
CVE-2026-65579

Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

9.8
CVE-2026-65578

Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

9.8
CVE-2026-65577

Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

9.8
CVE-2026-65576

Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

9.8
CVE-2026-65575

Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

9.8
CVE-2026-65574

Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

9.8
CVE-2026-65573

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

9.8
CVE-2026-65572

Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

9.8
CVE-2026-65571

Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

9.8
CVE-2026-65556

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

10.0
CVE-2026-65553

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

9.8
CVE-2026-65552

Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

9.9
CVE-2026-65548

Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

9.3
CVE-2026-65546

Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

9.3
CVE-2026-65520

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

9.3
CVE-2026-65508

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

9.8
CVE-2026-65507

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

9.1
CVE-2026-54489

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati

9.1
CVE-2026-53976

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and

9.8
CVE-2026-53975

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu

9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru

9.1
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses

9.8
CVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

9.8
CVE-2026-28005

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

9.8
CVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info

9.6
CVE-2026-12605

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started