Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 351/432
9.8
CVE-2022-27596

A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows

9.8
CVE-2023-0556

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on severa

9.1
CVE-2022-39811

Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGu

9.8
CVE-2022-48108

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettin

9.8
CVE-2022-48107

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettin

9.8
CVE-2022-48011

Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerr

9.8
CVE-2022-48008

An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary

9.8
CVE-2022-48066

An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a craf

9.8
CVE-2022-44298

SiteServer CMS 7.1.3 is vulnerable to SQL Injection.

9.8
CVE-2022-46967

An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admi

9.8
CVE-2022-46966

Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.

9.8
CVE-2022-42493

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A sp

9.8
CVE-2022-42492

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A sp

9.8
CVE-2022-42491

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A sp

9.8
CVE-2022-42490

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A sp

9.8
CVE-2022-41991

A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1

9.8
CVE-2022-41030

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41019

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41018

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41017

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41016

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41015

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41014

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41013

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41012

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41011

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41010

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41009

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41008

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41007

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41006

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41005

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41004

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41003

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41002

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41001

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-41000

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40999

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40998

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40997

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40996

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40995

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40994

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40993

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40992

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40991

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40990

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40989

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40988

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

9.8
CVE-2022-40987

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started