Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 65/432
9.8
CVE-2026-35300

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are

9.1
CVE-2026-35298

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are

9.8
CVE-2026-35296

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

9.9
CVE-2026-35294

Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Mainframe Connectors).

9.8
CVE-2026-35293

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supp

10.0
CVE-2026-35292

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that

9.8
CVE-2026-35286

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

9.9
CVE-2026-35285

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

9.9
CVE-2026-35284

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

9.9
CVE-2026-35283

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

9.9
CVE-2026-35282

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

9.9
CVE-2026-35281

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

9.9
CVE-2026-35280

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

9.8
CVE-2026-35278

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor).

9.1
CVE-2026-35270

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

9.9
CVE-2026-35268

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that ar

9.9
CVE-2026-35263

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are

9.1
CVE-2026-22313

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting a

9.8
CVE-2026-0126

In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execu

9.1
CVE-2026-53776

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by

9.1
CVE-2026-12316

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

9.1
CVE-2026-12315

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thund

9.1
CVE-2026-12304

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR

9.6
CVE-2026-12297

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox

9.6
CVE-2026-12296

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 1

9.6
CVE-2026-12295

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefo

9.6
CVE-2026-12294

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox E

9.8
CVE-2026-12293

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

9.9
CVE-2026-40750

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Sh

9.3
CVE-2026-52715

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

9.9
CVE-2026-49774

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inc

9.3
CVE-2026-49772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / Stell

9.3
CVE-2026-39574

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

9.1
CVE-2026-12205

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DS

9.1
CVE-2026-48714

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno

9.1
CVE-2026-48713

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missi

9.1
CVE-2026-12087

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the l

9.1
CVE-2026-11832

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was genera

9.8
CVE-2026-9691

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja For

9.6
CVE-2026-52703

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

9.3
CVE-2026-52693

Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

9.8
CVE-2026-49781

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

9.3
CVE-2026-49776

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websit

9.8
CVE-2026-49770

Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

9.8
CVE-2026-49769

Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

9.8
CVE-2026-49768

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

9.9
CVE-2026-49766

Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.

9.8
CVE-2026-49765

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <=

9.8
CVE-2026-49764

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

9.8
CVE-2026-49763

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started