Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 1010 of 1190
CVSS:9.8(Critical)

Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSCo...

CWE-782013
CVSS:9.8(Critical)

A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code

CWE-942013
CVSS:9.8(Critical)

There is an object injection vulnerability in swfupload plugin for wordpress.

CWE-202013
CVSS:9.8(Critical)

Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.

CVSS:9.8(Critical)

Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input

CWE-202013
CVSS:9.8(Critical)

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a Q...

CVSS:9.8(Critical)

A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.

CWE-202013
CVSS:9.8(Critical)

Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.

CVSS:9.8(Critical)

NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

CVSS:9.8(Critical)

XnView 2.03 has a stack-based buffer overflow vulnerability

CVSS:9.8(Critical)

Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.

CVSS:9.8(Critical)

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector...

CVSS:9.8(Critical)

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session,...

CVSS:9.8(Critical)

Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.

CVSS:9.8(Critical)

Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".

CVSS:9.8(Critical)

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

CVSS:9.8(Critical)

vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

CWE-742013
CVSS:9.8(Critical)

An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

CVSS:9.8(Critical)

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

CVSS:9.8(Critical)

An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

CVSS:9.8(Critical)

A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

CWE-222013
CVSS:9.8(Critical)

An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, caus...

CVSS:9.8(Critical)

NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.