Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 166 of 1190
CVSS:9.8(Critical)

Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.

CVSS:9.8(Critical)

Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.

CVSS:9.8(Critical)

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view_order.php. Th...

CWE-892024
CVSS:9.8(Critical)

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

CWE-892024
CVSS:9.8(Critical)

Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.

CWE-892024
CVSS:9.8(Critical)

Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.

CWE-892024
CVSS:9.8(Critical)

Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an authentication code. W...

CVSS:9.8(Critical)

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special f...

CWE-222024
CVSS:9.8(Critical)

Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

CVSS:9.8(Critical)

An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

CVSS:9.8(Critical)

xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

CWE-892024
CVSS:9.8(Critical)

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attacke...

CVSS:9.8(Critical)

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.

CWE-892024
CVSS:9.8(Critical)

Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.

CWE-892024
CVSS:9.8(Critical)

SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.

CWE-892024
CVSS:9.8(Critical)

Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

CWE-782024
CVSS:9.8(Critical)

The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() fu...

CVSS:9.8(Critical)

A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The manipulation of the argument ...

CVSS:9.8(Critical)

JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

CWE-892024
CVSS:9.8(Critical)

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted fil...

CVSS:9.8(Critical)

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter...

CVSS:9.8(Critical)

An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath a...

CVSS:9.8(Critical)

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.

CWE-892024
CVSS:9.8(Critical)

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list...

CWE-892024