Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 4/432
9.1
CVE-2026-77541

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability

9.1
CVE-2026-77540

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

9.1
CVE-2026-77539

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

10.0
CVE-2026-77537

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Pro

9.9
CVE-2026-77536

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f

9.1
CVE-2026-77535

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit

9.9
CVE-2026-77534

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f

9.8
CVE-2026-59683

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of

9.1
CVE-2026-59682

Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

9.8
CVE-2026-80235

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote atta

9.9
CVE-2026-77533

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability

9.8
CVE-2026-18431

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the

9.8
CVE-2026-19632

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive In

9.8
CVE-2026-80138

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to s

10.0
CVE-2026-79911

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the functio

9.1
CVE-2026-16645

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Bro

9.1
CVE-2026-16644

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST v

9.8
CVE-2026-16641

Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

9.8
CVE-2026-16639

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On all

9.1
CVE-2026-78655

Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earli

9.8
CVE-2026-78619

Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge beca

9.1
CVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security

9.8
CVE-2026-65905

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize req

9.8
CVE-2026-65637

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects

9.1
CVE-2026-65182

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a

9.8
CVE-2026-80104

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the uplo

9.6
CVE-2026-79290

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outsi

9.6
CVE-2026-79282

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbit

9.6
CVE-2026-79275

Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outs

9.6
CVE-2026-79257

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outs

9.6
CVE-2026-79235

Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outs

9.6
CVE-2026-79232

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrar

9.6
CVE-2026-79200

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outsi

9.6
CVE-2026-79189

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar

9.6
CVE-2026-79188

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar

9.8
CVE-2026-79152

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to

9.6
CVE-2026-79150

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary

9.6
CVE-2026-79149

Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outs

9.1
CVE-2026-79148

Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social enginee

9.6
CVE-2026-79140

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary

9.6
CVE-2026-79138

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia

9.6
CVE-2026-79131

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code

9.6
CVE-2026-79130

Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code out

9.6
CVE-2026-79129

Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging so

9.6
CVE-2026-79128

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary

9.6
CVE-2026-79111

Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execu

9.6
CVE-2026-79091

Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging socia

9.8
CVE-2026-79090

Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci

9.6
CVE-2026-79078

Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

9.6
CVE-2026-79064

Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started