Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 175/432
9.3
CVE-2025-47640

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcar

10.0
CVE-2025-47637

Unrestricted Upload of File with Dangerous Type vulnerability in STAGGS STAGGS staggs allows Upload a Web Shell to a Web

9.3
CVE-2025-47599

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturante Factura

9.8
CVE-2025-47568

Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue a

9.8
CVE-2025-47539

Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This iss

9.8
CVE-2025-47532

Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpay

9.8
CVE-2025-47530

Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affe

9.3
CVE-2025-46539

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFable Fable Extr

9.9
CVE-2025-46490

Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-co

9.8
CVE-2025-46468

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

9.3
CVE-2025-46460

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Detheme Easy Guide

9.3
CVE-2025-46455

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IndigoThemes WP HR

9.3
CVE-2025-39504

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlay

9.8
CVE-2025-39503

Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows Object Injection.This i

9.3
CVE-2025-39501

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlay

9.8
CVE-2025-39500

Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This

9.8
CVE-2025-39499

Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affec

9.8
CVE-2025-39495

Deserialization of Untrusted Data vulnerability in BoldThemes Avantage avantage allows Object Injection.This issue affec

9.8
CVE-2025-39489

Incorrect Privilege Assignment vulnerability in pebas CouponXL couponxl allows Privilege Escalation.This issue affects C

9.8
CVE-2025-39485

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue af

9.8
CVE-2025-39480

Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue a

9.8
CVE-2025-32292

Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress jarvis

9.8
CVE-2025-31927

Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola:

9.8
CVE-2025-31918

Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro

9.0
CVE-2025-31916

Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium

9.3
CVE-2025-31914

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel

9.8
CVE-2025-31631

Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue

9.8
CVE-2025-31430

Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The

9.8
CVE-2025-31423

Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affec

9.3
CVE-2025-31397

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticke

9.8
CVE-2025-31069

Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injecti

9.3
CVE-2025-31056

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCar

9.8
CVE-2025-31049

Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from

9.8
CVE-2025-5099

An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory c

9.1
CVE-2025-5098

PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's

9.1
CVE-2025-48373

Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to

9.8
CVE-2024-6914

An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account re

9.8
CVE-2024-41198

An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges

9.8
CVE-2024-41197

An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privilege

9.8
CVE-2024-41196

An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privi

9.8
CVE-2024-41195

An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate

9.0
CVE-2025-30171

System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator

9.1
CVE-2025-2410

Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session

9.1
CVE-2025-2409

File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator c

9.0
CVE-2024-48853

An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a

9.8
CVE-2025-32814

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

9.8
CVE-2025-3484

MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil

9.0
CVE-2025-34027

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy

9.8
CVE-2025-46412

Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authenticati

9.8
CVE-2025-41426

Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerabili

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started