Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 66/432
9.8
CVE-2026-49109

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, N

9.8
CVE-2026-49106

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.

9.8
CVE-2026-49105

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <=

9.8
CVE-2026-49104

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formid

9.8
CVE-2026-49085

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

9.3
CVE-2026-49067

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

9.3
CVE-2026-48886

Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.

9.1
CVE-2026-48881

Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

10.0
CVE-2026-48836

Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.

9.3
CVE-2026-45439

Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.

9.3
CVE-2026-42665

Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.

9.3
CVE-2026-42639

Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

9.3
CVE-2026-42386

Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.

9.3
CVE-2026-42381

Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.

9.3
CVE-2026-40798

Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.

10.0
CVE-2026-40772

Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.

9.3
CVE-2026-40771

Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.

9.9
CVE-2026-39591

Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.

9.8
CVE-2026-39583

Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

9.3
CVE-2026-39530

Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.

9.3
CVE-2026-39519

Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.

9.3
CVE-2026-39512

Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.

9.3
CVE-2026-39511

Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.

9.3
CVE-2026-39502

Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

9.3
CVE-2026-39493

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.

9.3
CVE-2026-39492

Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

9.1
CVE-2026-39465

Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.

9.3
CVE-2026-39441

Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.

9.8
CVE-2026-34901

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

9.8
CVE-2026-27053

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

9.8
CVE-2026-50890

Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /sto

9.1
CVE-2026-50887

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attac

9.1
CVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan inte

9.6
CVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute

9.8
CVE-2026-50880

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary cod

9.8
CVE-2026-50873

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to exec

9.8
CVE-2026-50872

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitra

9.8
CVE-2026-50871

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscenc

9.8
CVE-2026-50869

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplyi

9.1
CVE-2026-49952

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica

9.8
CVE-2026-48114

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab

9.1
CVE-2026-45390

In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire

9.1
CVE-2026-45388

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,

9.8
CVE-2026-39196

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in th

9.8
CVE-2026-39006

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component

9.8
CVE-2026-38812

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generatio

9.8
CVE-2026-38329

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoi

9.8
CVE-2026-38065

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the

9.8
CVE-2026-38064

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNu

9.8
CVE-2026-38063

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started