Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 172/432
9.8
CVE-2025-5288

The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri

9.8
CVE-2025-43863

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le

9.8
CVE-2024-56158

XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGE

9.8
CVE-2025-4973

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen

9.8
CVE-2022-4976

Archive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vul

9.8
CVE-2025-40912

CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds

9.8
CVE-2025-40914

Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a

9.3
CVE-2025-32711

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

9.8
CVE-2025-49710

An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Fir

9.8
CVE-2025-49709

Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

9.8
CVE-2025-41663

For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary comman

9.8
CVE-2025-2474

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker

9.8
CVE-2024-57190

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP

9.9
CVE-2025-40585

A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain

9.9
CVE-2025-30220

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Ecl

9.3
CVE-2024-34711

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne

9.8
CVE-2025-49507

Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affect

9.3
CVE-2025-49455

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Wor

9.1
CVE-2025-43698

Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level sec

9.8
CVE-2025-40657

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.8
CVE-2025-40656

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.8
CVE-2025-40655

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.8
CVE-2025-40654

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.9
CVE-2025-1041

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v

9.6
CVE-2025-42989

RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalatio

9.8
CVE-2025-30515

CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within

9.8
CVE-2025-30184

CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.

9.8
CVE-2025-49652

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts

9.0
CVE-2025-49136

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to versi

9.3
CVE-2025-48281

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform My

9.3
CVE-2025-48141

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Mult

9.9
CVE-2025-48140

Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi all

9.8
CVE-2025-48129

Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-co

10.0
CVE-2025-48123

Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer

9.3
CVE-2025-48122

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering

9.3
CVE-2025-47608

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sonalsinha21 Recov

10.0
CVE-2025-32291

Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Using

9.8
CVE-2025-31429

Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme all

9.3
CVE-2025-31424

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le

9.8
CVE-2025-31398

Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This i

9.8
CVE-2025-31396

Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. Thi

9.3
CVE-2025-31059

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in woobewoo WBW Produ

9.8
CVE-2025-31052

Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion

9.1
CVE-2025-31039

Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML

9.8
CVE-2025-31022

Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India payu-india allows Authen

9.3
CVE-2025-24767

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketB

9.9
CVE-2025-49013

WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across th

9.8
CVE-2025-48877

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t

9.6
CVE-2025-3835

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Cont

9.8
CVE-2025-5893

Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started