Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 62/432
9.1
CVE-2026-50203

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or

9.8
CVE-2026-49767

Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.

9.8
CVE-2026-49107

Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.

9.3
CVE-2026-49084

Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.

9.3
CVE-2026-49080

Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.

9.3
CVE-2026-49079

Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.

9.3
CVE-2026-49076

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

9.8
CVE-2026-49075

Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.

9.8
CVE-2026-49058

Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

9.3
CVE-2026-48875

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

9.9
CVE-2026-48781

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta

9.3
CVE-2026-48745

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca

9.3
CVE-2026-48616

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L

10.0
CVE-2026-48055

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,

9.8
CVE-2026-42380

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

9.9
CVE-2026-40783

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

9.9
CVE-2026-40749

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

9.9
CVE-2026-40748

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

9.9
CVE-2026-40747

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

9.9
CVE-2026-40746

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

9.8
CVE-2026-40725

Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

9.3
CVE-2026-39596

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

9.9
CVE-2026-39589

Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.

9.8
CVE-2026-39529

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

9.3
CVE-2026-39438

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

9.1
CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Ap

9.8
CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler

9.8
CVE-2026-27429

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

9.8
CVE-2026-27395

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

9.9
CVE-2026-27041

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

10.0
CVE-2026-25470

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin fo

9.9
CVE-2026-25446

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

9.1
CVE-2026-24611

Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.

9.3
CVE-2026-22340

Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

9.3
CVE-2026-22332

Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.

9.9
CVE-2026-22327

Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.

9.6
CVE-2026-12440

Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to po

9.8
CVE-2026-10094

A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS De

9.8
CVE-2025-69179

Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.

10.0
CVE-2025-69129

Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 vers

9.8
CVE-2025-69122

Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.

9.8
CVE-2025-69108

Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.

9.9
CVE-2025-60218

Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.

9.8
CVE-2025-60205

Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.

9.9
CVE-2024-52488

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

10.0
CVE-2026-46978

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported

9.9
CVE-2026-46964

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level

9.9
CVE-2026-46963

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level

9.1
CVE-2026-46949

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operatio

9.1
CVE-2026-46946

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started