Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 9/432
9.9
CVE-2026-73992

Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.

9.3
CVE-2026-68566

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

9.8
CVE-2026-66682

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

9.3
CVE-2026-66680

Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

9.8
CVE-2026-66672

Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

9.3
CVE-2026-66649

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

9.3
CVE-2026-66609

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

9.1
CVE-2026-66600

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

9.3
CVE-2026-66593

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

9.3
CVE-2026-66592

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

9.8
CVE-2026-66583

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

9.8
CVE-2025-15689

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

9.3
CVE-2025-15688

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

9.6
CVE-2026-11861

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Direct

9.8
CVE-2026-14950

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session aft

9.8
CVE-2026-75860

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its a

9.8
CVE-2026-76850

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch

9.9
CVE-2026-76590

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionalit

9.9
CVE-2026-76589

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/my

9.1
CVE-2026-76404

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands

9.4
CVE-2026-76312

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hyperte

9.4
CVE-2026-76311

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo

9.4
CVE-2026-76310

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo

9.9
CVE-2026-76584

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionali

9.6
CVE-2026-53548

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

9.6
CVE-2026-53546

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

9.8
CVE-2026-53545

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

9.8
CVE-2026-63722

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to ex

9.9
CVE-2026-55089

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authoriz

9.6
CVE-2026-55085

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates

10.0
CVE-2026-22306

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans

9.8
CVE-2026-19508

Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10

9.8
CVE-2026-19505

Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allow

9.8
CVE-2026-16919

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper va

9.8
CVE-2026-16917

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer

9.8
CVE-2026-16913

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

9.6
CVE-2026-16903

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial

9.8
CVE-2026-16894

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

9.8
CVE-2026-16885

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

9.8
CVE-2026-16882

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

9.8
CVE-2026-16872

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-bas

9.8
CVE-2026-16864

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

9.8
CVE-2026-16862

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

9.8
CVE-2026-16845

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buff

9.8
CVE-2026-16840

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-b

9.4
CVE-2026-16839

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an in

9.8
CVE-2026-16834

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integ

9.3
CVE-2026-16822

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and mod

9.9
CVE-2026-70496

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator

9.8
CVE-2026-18315

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Thr

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started