Top 50 Critical Vulnerabilities with Exploit/Exploitation Context (2022–2026)
CVEs in the Known Exploited Vulnerabilities catalog (KEV) are those observed exploits in real attacks on organizations.
1–10: Actively Exploited / Known Exploits
CVE-2025-55182 — React/Next.js RCE (10.0) — actively exploited.
CVE-2025-64446 — Fortinet FortiWeb auth bypass & admin creation (9.8) — in the wild.
CVE-2025-53770 — MS SharePoint ToolShell RCE (9.8) — known active exploit.
CVE-2025-61882 — Oracle EBS BI Publisher RCE (9.8) — exploited.
CVE-2025-20333 — Cisco ASA/FTD buffer overflow RCE (9.9) — CISA KEV.
CVE-2025-5777 — Citrix NetScaler memory flaw (CitrixBleed 2) — active.
CVE-2025-32463 — Sudo privilege escalation — KEV.
CVE-2025-3248 — Langflow AI Platform unauth RCE (9.8) — KEV.
CVE-2025-48633 — Android critical info disclosure (zero-day) — limited exploit.
CVE-2025-48572 — Android elevation of privilege — exploited.
11–20: Other Critical Exploited CVEs (KEV / Known Exploit)
CVE-2025-50165 — Microsoft Graphics Component RCE (9.8).
CVE-2025-53767 — Azure OpenAI data access RCE (10.0).
CVE-2025-53792 — Microsoft remote code execution.
CVE-2025-53766 — Microsoft critical web-based exploit.
CVE-2025-48631 — Android DoS / RCE (critical).
CVE-2025-43529 — Apple WebKit RCE (zero-day targeted).
CVE-2025-14174 — Apple WebKit memory corruption RCE.
CVE-2025-14847 — MongoDB “MongoBleed” PoC exploit.
CVE-2026-20805 — Microsoft Windows information disclosure — on top 100 list.
CVE-2025-68613 — n8n libraries improper control — with public exploits.
21–30: Exploitable Vulnerabilities with Public Proof-of-Concept
CVE-2025-38352 — Linux kernel race condition (exploit PoC).
CVE-2025-43529 — WebKitGTK use-after-free — Apple and others.
CVE-2025-37164 — HPE OneView code injection with public exploit.
CVE-2025-59718 — FortiOS crypto verification bypass.
CVE-2025-7775 — Citrix NetScaler ADC buffer overflow.
CVE-2025-14174 — WebKit Chromium mem corruption (public PoC).
CVE-2025-37164 — Code injection in other major tools.
CVE-2025-31161 — CrushFTP missing auth — public exploit seen.
CVE-2025-2825 — CrushFTP auth bypass variant exploited.
CVE-2025-10035 — GoAnywhere MFT deserialization abuse (ransomware).
31–40: Other Known Exploited / Weaponized Vulnerabilities
CVE-2019-19781 — Citrix ADC/Gateway RCE (still exploited historically).
CVE-2019-6693 — FortiOS hardcoded credentials (ransomware use).
CVE-2025-24472 — Fortinet FortiOS/Proxy auth bypass.
CVE-2024-55591 — Fortinet FortiOS and FortiProxy auth bypass.
CVE-2025-5777 — Citrix ADC unsafe memory read.
CVE-2025-32463 — Sudo escalation.
CVE-2021-44228 (Log4Shell) — ubiquitous Java RCE still exploited in environments.
CVE-2024-34102 — Adobe Commerce XXE RCE (CISA KEV).
CVE-2025-32709 — Windows zero-day RCE sample with PoC.
CVE-2025-32702 — Windows proof-of-concept exploit.
41–50: Historical / High-Impact Exploited Vulnerabilities You Should Still Track
CVE-2017-0144 (EternalBlue) — Windows SMB RCE used by WannaCry.
CVE-2017-8759 — .NET remote code execution used by malware.
CVE-2018-4878 — Adobe Flash RCE exploited by DOGCALL malware.
CVE-2023-3519 — Citrix ADC RCE (real infrastructure compromise).
CVE-2023-3466 / 67 — Citrix ADC appliances exploited together.
CVE-2023-4966 — Citrix CitrixBleed buffer overflow attack.
CVE-2023-20198 — Cisco IOS XE privilege escalation exploits.
CVE-2024-50302 — Android zero-day exploited (historical).
CVE-2024-43093 — Android zero-day exploited.
CVE-2024-12084 — Rsync critical RCE with public proof-of-concept.

