Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 8/432
9.8
CVE-2026-77647

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August

9.8
CVE-2026-72843

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/

9.9
CVE-2026-69851

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a

10.0
CVE-2026-69836

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

10.0
CVE-2026-69555

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

9.6
CVE-2026-69400

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize

9.9
CVE-2026-68789

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut

9.9
CVE-2026-68782

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut

9.1
CVE-2026-66309

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

10.0
CVE-2026-65816

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a

10.0
CVE-2026-65801

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov

10.0
CVE-2026-65770

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache

9.9
CVE-2026-63509

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

9.3
CVE-2026-62834

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil

9.9
CVE-2026-18835

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands

9.3
CVE-2026-17422

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer ove

9.8
CVE-2026-17160

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer

9.8
CVE-2026-17157

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

9.8
CVE-2026-17152

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov

9.8
CVE-2026-17145

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper pr

9.8
CVE-2026-17142

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

9.8
CVE-2026-17141

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov

9.8
CVE-2026-17136

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format st

9.8
CVE-2026-17122

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-bas

9.8
CVE-2026-17118

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after

9.8
CVE-2026-17040

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov

9.1
CVE-2026-71485

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlle

9.9
CVE-2026-67567

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the abi

9.8
CVE-2026-43798

A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controll

9.9
CVE-2026-77148

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-con

9.9
CVE-2026-66788

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where th

9.9
CVE-2026-66785

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from o

9.1
CVE-2026-73257

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can sen

9.1
CVE-2026-73256

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an

9.9
CVE-2026-77022

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the

9.3
CVE-2026-71428

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc

9.8
CVE-2026-55642

dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/au

9.8
CVE-2026-18265

OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attacker

9.8
CVE-2026-63039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-63038

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-63037

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.1
CVE-2026-16926

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper

9.8
CVE-2026-15706

Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Bayla

9.6
CVE-2026-28164

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery.

9.8
CVE-2026-18482

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-

9.9
CVE-2026-74018

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

9.9
CVE-2026-74016

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

9.9
CVE-2026-74014

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

9.8
CVE-2026-74001

Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

9.8
CVE-2026-73993

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started