Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 381/432
9.8
CVE-2022-32993

TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

10.0
CVE-2022-32548

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin

9.8
CVE-2022-22897

A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder

9.8
CVE-2022-25644

All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitiz

9.8
CVE-2022-21165

All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of inpu

9.8
CVE-2022-34668

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma

9.8
CVE-2022-36572

Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability v

9.8
CVE-2022-36708

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/

9.8
CVE-2022-36706

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at

9.8
CVE-2022-36705

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at

9.8
CVE-2022-38555

Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

9.8
CVE-2022-37056

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin,

9.8
CVE-2022-37055 KEV

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, h

9.8
CVE-2022-38557

D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

9.8
CVE-2022-38556

Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

9.8
CVE-2022-37057

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin,

9.8
CVE-2022-37053

TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.

9.8
CVE-2022-36756

DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

9.8
CVE-2022-36755

D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request

9.8
CVE-2022-38792

The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.

9.1
CVE-2019-15167

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a differ

9.8
CVE-2022-36545

Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p

9.8
CVE-2022-36544

Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p

9.8
CVE-2022-36543

Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p

9.8
CVE-2022-37152

An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob"

9.8
CVE-2022-36683

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas

9.8
CVE-2022-36682

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas

9.8
CVE-2022-36681

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas

9.8
CVE-2022-36680

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas

9.8
CVE-2022-36679

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admi

9.8
CVE-2022-36678

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas

9.8
CVE-2022-31499

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via Reade

9.8
CVE-2022-28747

Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To explo

9.8
CVE-2022-36719

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/hi

9.8
CVE-2022-36716

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ch

9.8
CVE-2022-36715

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/

9.8
CVE-2022-36697

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

9.8
CVE-2022-36696

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

9.8
CVE-2022-36695

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

9.8
CVE-2022-36693

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

9.8
CVE-2022-36692

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

9.8
CVE-2021-43329

A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attac

9.8
CVE-2022-37159

Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

9.8
CVE-2022-37158

RuoYi v3.8.3 has a Weak password vulnerability in the management system.

9.8
CVE-2022-37816

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.

9.8
CVE-2022-37815

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function for

9.8
CVE-2022-37814

Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id paramet

9.8
CVE-2022-37813

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.

9.8
CVE-2022-37812

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSe

9.8
CVE-2022-37811

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPP

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started