Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 774 of 1190
CVSS:9.8(Critical)

SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.

CWE-892018
CVSS:9.8(Critical)

SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.

CWE-892018
CVSS:9.8(Critical)

SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.

CWE-892018
CVSS:9.8(Critical)

An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18...

CVSS:9.8(Critical)

When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issue affects WhatsApp for Android prior to 2.18.24...

CVSS:9.8(Critical)

The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be cre...

CVSS:9.8(Critical)

react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, all...

CWE-782018
CVSS:9.8(Critical)

When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in. An off-by-one error meant that data was written beyond the allocat...

CVSS:9.8(Critical)

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This...

CVSS:9.8(Critical)

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content insid...

CWE-792018
CVSS:9.8(Critical)

Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versio...

CVSS:9.8(Critical)

It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on ...

CWE-892018
CVSS:9.8(Critical)

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into ...

CVSS:9.8(Critical)

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before...

CWE-202018
CVSS:9.8(Critical)

Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Campaigns\utils.php, the default_currency_name paramet...

CWE-892018
CVSS:9.8(Critical)

Remote code execution in Hanwha Techwin Smartcams

CWE-202018
CVSS:9.8(Critical)

Unencrypted way of remote control and communications in Hanwha Techwin Smartcams

CVSS:9.8(Critical)

Unsecured way of firmware update in Hanwha Techwin Smartcams

CVSS:9.8(Critical)

Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.

CWE-742018
CVSS:9.8(Critical)

A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vu...

CWE-782018