Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CRITICAL Severity CVEs

CVSS 9.0 – 10.0

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

35,149
Total
312
Known Exploited
Showing 21,564 of 35,149 total · Page 42/432
10.0
CVE-2026-47056

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported ve

9.1
CVE-2026-47040

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are

9.8
CVE-2026-47036

Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supporte

9.8
CVE-2026-46994

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next

9.1
CVE-2026-46989

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framewo

9.8
CVE-2026-46983

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The

9.8
CVE-2026-46982

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The

9.8
CVE-2026-46924

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita

9.8
CVE-2026-46876

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita

9.8
CVE-2026-35290

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita

9.8
CVE-2026-8983

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorizati

9.3
CVE-2026-65057

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make

9.8
CVE-2026-52472

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml

9.8
CVE-2026-52470

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper

9.8
CVE-2026-52469

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.

9.8
CVE-2026-30631

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers

9.9
CVE-2026-64879

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing

9.9
CVE-2026-64878

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting

9.8
CVE-2026-59147

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent i

9.1
CVE-2026-59145

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena i

9.8
CVE-2026-59144

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in rin

9.8
CVE-2026-50755

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwar

9.1
CVE-2026-59142

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and leng

9.1
CVE-2026-59141

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices

9.1
CVE-2026-59140

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the ra

9.1
CVE-2026-59139

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and lengt

9.6
CVE-2026-16441

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been

9.8
CVE-2016-20096

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows r

9.6
CVE-2026-47416

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnera

9.6
CVE-2026-47413

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivi

9.1
CVE-2026-16439

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

9.8
CVE-2026-47410

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an ins

9.3
CVE-2026-64825

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to wri

9.8
CVE-2026-47396

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent

9.8
CVE-2026-47393

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-gene

9.9
CVE-2026-47392

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso

9.8
CVE-2026-47391

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an

9.1
CVE-2026-28321

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, w

9.1
CVE-2026-28317

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc

9.1
CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc

9.1
CVE-2026-28314

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us

9.1
CVE-2026-28313

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin

9.1
CVE-2026-28312

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system adm

9.1
CVE-2026-28310

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the

9.1
CVE-2026-28309

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst

9.1
CVE-2026-28308

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e

9.1
CVE-2026-28307

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated int

9.1
CVE-2026-28306

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate thei

9.1
CVE-2026-28305

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e

9.1
CVE-2026-28304

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary exe

Frequently Asked Questions

What does CRITICAL severity mean for CVEs?

CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required

How many critical severity CVEs exist?

There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize critical severity vulnerabilities?

CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect CRITICAL Vulnerabilities

CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.

Get Started