Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 379 of 1190
CVSS:9.8(Critical)

Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet....

CVSS:9.8(Critical)

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

CVSS:9.8(Critical)

Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

CVSS:9.8(Critical)

SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.

CWE-892022
CVSS:9.8(Critical)

SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php

CWE-772022
CVSS:9.8(Critical)

A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of th...

CVSS:9.8(Critical)

Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.

CWE-892022
CVSS:9.8(Critical)

In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

CVSS:9.8(Critical)

An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.

CWE-892022
CVSS:9.8(Critical)

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted ...

CWE-942022
CVSS:9.8(Critical)

Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").

CVSS:9.8(Critical)

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

CVSS:9.8(Critical)

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/

CVSS:9.8(Critical)

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/

CVSS:9.8(Critical)

Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/

CVSS:9.8(Critical)

Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet

CVSS:9.8(Critical)

Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting

CVSS:9.8(Critical)

Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList

CVSS:9.8(Critical)

Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (...

CVSS:9.8(Critical)

Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set

CVSS:9.8(Critical)

Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set

CVSS:9.8(Critical)

Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.

CVSS:9.8(Critical)

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability

CWE-892022
CVSS:9.8(Critical)

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not...

CWE-892022