Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 48/432
9.8
CVE-2026-53633

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo

9.6
CVE-2026-48359

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t

9.1
CVE-2026-48358

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co

9.3
CVE-2026-48356

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi

9.6
CVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrar

9.8
CVE-2026-47429

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile

9.6
CVE-2026-47428

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v

10.0
CVE-2026-15409 KEV

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A

9.8
CVE-2026-13001

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali

9.8
CVE-2026-47767

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.

9.1
CVE-2026-45069

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1

9.1
CVE-2026-45063

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

9.9
CVE-2026-57092

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

9.8
CVE-2026-56190

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-56188

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network dr

9.8
CVE-2026-56159

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-55944

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a netwo

9.1
CVE-2026-55040 KEV

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n

9.8
CVE-2026-55010

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a

9.8
CVE-2026-50518

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-50447

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

9.6
CVE-2026-50380

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

9.1
CVE-2026-15747

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH

9.6
CVE-2026-59891

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials

9.8
CVE-2026-58644 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a

9.6
CVE-2026-55008

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows

9.8
CVE-2026-54990

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-54118

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-54117

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

9.1
CVE-2026-54058

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename

9.8
CVE-2026-50522 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a

9.3
CVE-2026-49798

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

9.8
CVE-2026-49172

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

9.6
CVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all

9.8
CVE-2026-42990

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

9.8
CVE-2026-15701

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo

9.1
CVE-2026-60082

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle

9.8
CVE-2026-58479

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional

9.1
CVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitr

9.8
CVE-2026-62392

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin

9.8
CVE-2026-62390

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A ba

10.0
CVE-2026-62422

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 aut

9.1
CVE-2026-58319

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated

10.0
CVE-2026-56451

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate

9.1
CVE-2026-3014

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerabilit

9.8
CVE-2026-15043

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano,

9.1
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the Enc

9.1
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra

9.0
CVE-2026-57898

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backen

9.6
CVE-2026-11563

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletio

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started