Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 7/432
9.8
CVE-2026-74617

In the Linux kernel, the following vulnerability has been resolved: dibs: initialise dibs->lock in dibs_dev_alloc() di

9.8
CVE-2026-74616

In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_info tai

10.0
CVE-2026-74612

In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adju

9.8
CVE-2026-74611

In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic

9.8
CVE-2026-74608

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_adding_

9.8
CVE-2026-74597

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip

9.8
CVE-2026-74591

In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index bef

9.8
CVE-2026-74588

In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list i

9.8
CVE-2026-74587

In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk ad

9.8
CVE-2026-74586

In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sct

9.8
CVE-2026-4703

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all ve

9.1
CVE-2026-75870

Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared

9.1
CVE-2026-75866

Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant t

10.0
CVE-2026-77946

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe

9.8
CVE-2026-78003

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in

9.8
CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity

9.8
CVE-2026-77001

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authen

9.8
CVE-2026-77000

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with

9.1
CVE-2026-49849

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allo

9.8
CVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to v

9.9
CVE-2026-62283

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 t

10.0
CVE-2026-61539

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference

9.9
CVE-2026-77810

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties i

9.0
CVE-2026-62674

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /ses

9.8
CVE-2026-74581

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_

10.0
CVE-2026-69502

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a ne

9.6
CVE-2026-77087

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbit

9.9
CVE-2026-63343

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadat

9.9
CVE-2026-63125

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus

9.9
CVE-2026-62941

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across project

9.9
CVE-2026-62940

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another c

9.9
CVE-2026-62867

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `b

9.9
CVE-2026-48769

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the I

9.9
CVE-2026-48755

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided ba

9.9
CVE-2026-48753

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vuln

9.9
CVE-2026-48752

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance b

9.9
CVE-2026-48751

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restrict

9.9
CVE-2026-48750

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/

9.9
CVE-2026-48749

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used t

9.8
CVE-2026-77806

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August

9.1
CVE-2026-77776

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at

9.9
CVE-2026-77683

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the fil

9.1
CVE-2026-77086

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing aut

9.1
CVE-2026-62440

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant mani

9.1
CVE-2026-61398

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password func

9.1
CVE-2026-59085

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery

9.8
CVE-2026-77264

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne

9.8
CVE-2026-77651

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,

9.8
CVE-2026-77650

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the

9.8
CVE-2026-77649

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started