Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 152/432
9.8
CVE-2022-50235

In the Linux kernel, the following vulnerability has been resolved: NFSD: Protect against send buffer overflow in NFSv2

9.8
CVE-2025-59361

The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20

9.8
CVE-2025-59360

The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20

9.8
CVE-2025-59359

The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59

9.8
CVE-2025-10432

A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of th

9.8
CVE-2025-10452

Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remo

9.8
CVE-2025-10392

A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the compon

9.1
CVE-2025-45583

Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenti

9.8
CVE-2025-58434

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, t

9.8
CVE-2024-45434

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo

9.8
CVE-2025-55835

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filteri

9.8
CVE-2025-9556

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5

9.1
CVE-2025-8699

Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use th

9.8
CVE-2025-10266

NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i

10.0
CVE-2025-10264

Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthentic

9.8
CVE-2025-10127

Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerabilit

9.6
CVE-2025-59053

AIRI is a self-hosted, artificial intelligence based Grok Companion. In v0.7.2-beta.2 in the `packages/stage-ui/src/comp

9.8
CVE-2025-39758

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sen

9.8
CVE-2025-58143

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

9.8
CVE-2025-58142

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

9.8
CVE-2025-27466

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

9.8
CVE-2025-40692

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre

9.8
CVE-2025-40691

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre

9.8
CVE-2025-40690

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre

9.8
CVE-2025-40689

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre

9.8
CVE-2025-40687

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre

10.0
CVE-2025-58321

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

9.8
CVE-2025-8570

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen

9.8
CVE-2025-54123

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i

9.8
CVE-2025-59041

Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema

9.8
CVE-2025-58764

Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to

9.8
CVE-2025-10226

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.

9.8
CVE-2025-10220

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.

9.1
CVE-2025-9943

An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t

9.8
CVE-2025-59046

The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc

9.1
CVE-2025-58448

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior

9.8
CVE-2025-58447

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior

9.6
CVE-2025-58768

DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering compo

9.8
CVE-2025-58462

OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A r

9.8
CVE-2025-57633

A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute

9.8
CVE-2025-43491

A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi

9.8
CVE-2025-10159

An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi

9.1
CVE-2025-58762

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attac

9.1
CVE-2025-44594

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/a

10.0
CVE-2025-55730

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in

10.0
CVE-2025-55729

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in

10.0
CVE-2025-55728

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in

10.0
CVE-2025-55727

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in

10.0
CVE-2025-55051

CWE-1392: Use of Default Credentials

9.8
CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started