Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

14,853
Total
68
Known Exploited
Showing 6,448 of 14,853 total · Page 3/129
9.8
CVE-2026-75330

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerab

9.8
CVE-2026-75329

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanis

9.1
CVE-2025-51679

An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected

9.8
CVE-2026-60004 KEV

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

9.8
CVE-2026-26448

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection,

9.8
CVE-2025-70290

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c

9.8
CVE-2026-75325

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param

9.1
CVE-2026-70419

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an

9.3
CVE-2026-51106

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.c

9.8
CVE-2025-61165

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac

9.8
CVE-2025-61163

Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This

9.8
CVE-2026-81032

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service d

9.8
CVE-2026-80428

ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components

9.8
CVE-2026-54569

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SE

9.8
CVE-2026-80589

In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a neve

9.8
CVE-2026-80587

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions So

9.8
CVE-2026-80586

In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpec

9.4
CVE-2026-80585

In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN

9.8
CVE-2026-80561

In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_lock

9.8
CVE-2026-80558

In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from prima

9.8
CVE-2026-80557

In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via miss

9.3
CVE-2026-80554

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program

9.3
CVE-2026-80551

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant

9.8
CVE-2026-80528

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal

9.8
CVE-2026-80519

In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer re

9.8
CVE-2026-74752

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When c

9.4
CVE-2026-74751

In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boun

9.8
CVE-2026-74746

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last

9.8
CVE-2026-74744

In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom

9.8
CVE-2026-74743

In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroo

9.8
CVE-2026-74737

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extr

9.6
CVE-2026-54523

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the Namespace

9.1
CVE-2026-75896

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows

9.8
CVE-2026-80203

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function

9.8
CVE-2026-77557

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote

10.0
CVE-2026-77554

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal

9.9
CVE-2026-77553

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f

9.8
CVE-2026-77552

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Ent

9.0
CVE-2026-77551

A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulne

10.0
CVE-2026-77550

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability fo

9.0
CVE-2026-77549

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CR

9.9
CVE-2026-77548

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability

9.9
CVE-2026-77547

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability

9.9
CVE-2026-77546

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability

9.6
CVE-2026-77532

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-ena

9.8
CVE-2026-18080

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi

9.8
CVE-2026-80349

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's

9.0
CVE-2026-77545

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug

9.9
CVE-2026-77543

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability

9.1
CVE-2026-77542

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 14,853 CVE records rated CRITICAL in our database. Of these, 68 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started