Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 328 of 1190
CVSS:9.8(Critical)

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

CWE-892023
CVSS:9.8(Critical)

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/user/manage_user.php. T...

CWE-892023
CVSS:9.8(Critical)

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: ...

CWE-942023
CVSS:9.8(Critical)

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/services/manage_service...

CWE-892023
CVSS:9.8(Critical)

Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).

CVSS:9.8(Critical)

Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.

CVSS:9.8(Critical)

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/inquiries/view_inquiry.php. The ...

CWE-892023
CVSS:9.8(Critical)

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CWE-892023
CVSS:9.8(Critical)

Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously craf...

CVSS:9.8(Critical)

Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously craf...

CVSS:9.8(Critical)

The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx a...

CVSS:9.8(Critical)

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote at...

CVSS:9.8(Critical)

A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=de...

CVSS:9.8(Critical)

A vulnerability has been found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Mast...

CWE-892023
CVSS:9.8(Critical)

Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution

CVSS:9.8(Critical)

Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability

CVSS:9.8(Critical)

Microsoft Outlook Elevation of Privilege Vulnerability

CWE-202023
CVSS:9.8(Critical)

HTTP Protocol Stack Remote Code Execution Vulnerability

CVSS:9.8(Critical)

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have a...

CWE-772023
CVSS:9.8(Critical)

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have a...

CWE-782023
CVSS:9.8(Critical)

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecif...

CVSS:9.8(Critical)

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecifi...

CVSS:9.8(Critical)

There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.

CWE-772023