Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 6/432
9.8
CVE-2026-78262

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

9.8
CVE-2026-32563

Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

9.9
CVE-2026-32559

Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

9.3
CVE-2026-32555

Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

9.3
CVE-2026-32554

Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

9.8
CVE-2026-52490

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the proces

9.1
CVE-2026-76835

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b

9.1
CVE-2026-71933

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul

9.8
CVE-2026-71921

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter

9.8
CVE-2026-71914

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i

9.8
CVE-2026-78329

Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1

9.8
CVE-2026-77915

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t

9.8
CVE-2026-71300

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam

9.1
CVE-2026-66906

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:

9.8
CVE-2026-76071

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated

9.8
CVE-2026-76070

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated

9.1
CVE-2026-19874

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation

9.6
CVE-2026-76840

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper

9.1
CVE-2026-67602

phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attacke

9.1
CVE-2026-59568

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthe

9.1
CVE-2026-59564

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and th

9.8
CVE-2026-66650

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

9.8
CVE-2026-66648

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

9.8
CVE-2026-66587

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

9.8
CVE-2026-32558

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

9.3
CVE-2026-32551

Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

9.8
CVE-2026-28165

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

9.9
CVE-2026-66897

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions,

9.8
CVE-2026-78211

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remo

9.9
CVE-2026-78169

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file

9.8
CVE-2026-78168

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_

10.0
CVE-2026-78167

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session

9.4
CVE-2026-78207

exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto_

9.8
CVE-2026-78183

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th

9.8
CVE-2026-8445

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in

9.8
CVE-2026-7808

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g.,

9.8
CVE-2026-5388

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_st

9.9
CVE-2026-78155

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privi

9.8
CVE-2026-13598

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, al

9.9
CVE-2026-78050

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-b

9.8
CVE-2026-74730

In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STAT

9.8
CVE-2026-74727

In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by

9.8
CVE-2026-74723

In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid hea

9.3
CVE-2026-74712

In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys(

10.0
CVE-2026-74705

In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segment

9.8
CVE-2026-74688

In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being

9.8
CVE-2026-74669

In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP

9.1
CVE-2026-74665

In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic XDP fr

9.8
CVE-2026-74662

In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer in

9.8
CVE-2026-74628

In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its ti

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started