Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 890 of 1190
CVSS:9.8(Critical)

The module pandora-doomsday infects other modules. It's since been unpublished from the registry.

CVSS:9.8(Critical)

dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.

CWE-942017
CVSS:9.8(Critical)

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely...

CWE-942017
CVSS:9.8(Critical)

Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.

CWE-942017
CVSS:9.8(Critical)

Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.

CWE-942017
CVSS:9.8(Critical)

IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compro...

CVSS:9.8(Critical)

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an...

CVSS:9.8(Critical)

rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has signif...

CVSS:9.8(Critical)

Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.

CWE-892017
CVSS:9.8(Critical)

Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.

CWE-892017
CVSS:9.8(Critical)

Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, ...

CWE-892017
CVSS:9.8(Critical)

Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.

CVSS:9.8(Critical)

Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.

CWE-892017
CVSS:9.8(Critical)

Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.

CWE-892017
CVSS:9.8(Critical)

Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.

CWE-892017
CVSS:9.8(Critical)

CPA Lead Reward Script allows SQL Injection via the username parameter.

CWE-892017
CVSS:9.8(Critical)

Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.

CWE-892017
CVSS:9.8(Critical)

Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.

CWE-892017
CVSS:9.8(Critical)

MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

CWE-892017
CVSS:9.8(Critical)

Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

CWE-892017
CVSS:9.8(Critical)

Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

CWE-892017
CVSS:9.8(Critical)

US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.

CWE-892017
CVSS:9.8(Critical)

Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.

CWE-892017
CVSS:9.8(Critical)

AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.

CWE-892017