Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 37/432
9.8
CVE-2026-65687

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG p

9.1
CVE-2026-65907

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

9.6
CVE-2026-65606

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://pl

9.6
CVE-2026-65605

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A

9.6
CVE-2026-65471

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

9.1
CVE-2026-65461

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

9.1
CVE-2026-65455

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

10.0
CVE-2026-64813

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

10.0
CVE-2026-64812

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

9.8
CVE-2026-61951

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

9.3
CVE-2026-61950

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

9.3
CVE-2026-61949

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

9.3
CVE-2026-61948

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

10.0
CVE-2026-59555

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

9.8
CVE-2026-59544

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

9.9
CVE-2026-59543

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

9.8
CVE-2026-59540

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

9.3
CVE-2026-59526

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

9.3
CVE-2026-59525

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

9.3
CVE-2026-59514

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

9.6
CVE-2026-57784

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

9.1
CVE-2026-27064

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

9.8
CVE-2026-65431

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extr

9.8
CVE-2026-64874

Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed i

9.8
CVE-2026-64873

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or re

9.8
CVE-2026-15015

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u

9.8
CVE-2026-15011

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame

9.8
CVE-2026-14282

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for

9.0
CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable

9.8
CVE-2026-60372

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.9
CVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.8
CVE-2026-60367

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

10.0
CVE-2026-60366

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.1
CVE-2026-64798

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also

9.8
CVE-2026-64796

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both t

9.1
CVE-2026-64793

Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere ext

9.8
CVE-2025-50329

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec

9.6
CVE-2026-16624

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on

9.1
CVE-2026-46738

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the

9.1
CVE-2026-40712

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the

9.8
CVE-2026-16606

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow

9.8
CVE-2026-2395

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info

9.1
CVE-2026-62144

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an

9.3
CVE-2026-50252

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret

9.8
CVE-2026-16232 KEV

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at

9.8
CVE-2026-65590

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/

9.8
CVE-2026-56817

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug

9.6
CVE-2026-16424

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised

9.6
CVE-2026-16419

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to p

9.3
CVE-2026-16416

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started