Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported ve
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are
Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supporte
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framewo
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorizati
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make
SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.
An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting
Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent i
Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena i
Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in rin
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwar
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and leng
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices
Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the ra
Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and lengt
In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows r
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnera
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivi
In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an ins
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to wri
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent
PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-gene
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, w
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system adm
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated int
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate thei
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary exe
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started