Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 5/432
9.1
CVE-2026-79058

Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

9.6
CVE-2026-79056

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute

9.6
CVE-2026-79052

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outsi

9.6
CVE-2026-79047

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

9.6
CVE-2026-79043

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar

9.6
CVE-2026-79026

Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social enginee

9.6
CVE-2026-79019

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia

9.6
CVE-2026-79012

Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging so

9.6
CVE-2026-78989

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential

9.6
CVE-2026-78985

Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragin

9.6
CVE-2026-78964

Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execut

9.6
CVE-2026-78951

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary c

9.6
CVE-2026-78948

Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code out

9.6
CVE-2026-78945

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

9.6
CVE-2026-78939

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

9.6
CVE-2026-78937

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging soci

9.6
CVE-2026-78935

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to p

9.6
CVE-2026-78909

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

9.6
CVE-2026-78904

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra

9.6
CVE-2026-78900

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec

9.9
CVE-2026-65093

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit

9.9
CVE-2026-65083

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an in

9.8
CVE-2026-45018

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,

9.8
CVE-2026-79787

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauth

10.0
CVE-2026-76197

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co

10.0
CVE-2026-76195

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co

10.0
CVE-2026-76193

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbi

9.8
CVE-2026-79675

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a

9.1
CVE-2026-55640

Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.11

9.8
CVE-2026-55546

QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engin

9.1
CVE-2026-55536

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome ex

9.8
CVE-2025-71407

Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors wi

9.8
CVE-2024-58378

Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free

9.8
CVE-2022-51000

Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which ar

9.8
CVE-2026-16286

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware

9.8
CVE-2026-79657

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir

9.1
CVE-2026-55976

Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated r

9.8
CVE-2026-49845

SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows

9.8
CVE-2026-78570

The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0

9.8
CVE-2026-78568

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due

9.8
CVE-2026-63586

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication u

9.1
CVE-2026-59769

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel'

9.8
CVE-2026-78477

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This mak

9.8
CVE-2026-13214

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When hand

9.6
CVE-2026-78683

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Transition

9.8
CVE-2026-78676

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting do

9.8
CVE-2026-56710

Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAc

9.8
CVE-2026-56705

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated a

9.8
CVE-2026-78267

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

9.8
CVE-2026-78265

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started