Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 917 of 1190
CVSS:9.8(Critical)

Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution

CWE-892017
CVSS:9.8(Critical)

Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution.

CVSS:9.8(Critical)

rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions

CVSS:9.8(Critical)

b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution...

CWE-202017
CVSS:9.8(Critical)

Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution

CVSS:9.8(Critical)

The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows...

CVSS:9.8(Critical)

NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This af...

CVSS:9.8(Critical)

A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and pos...

CVSS:9.8(Critical)

A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenB...

CVSS:9.8(Critical)

The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encry...

CVSS:9.8(Critical)

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers...

CVSS:9.8(Critical)

Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis

CVSS:9.8(Critical)

The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.

CVSS:9.8(Critical)

I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.

CVSS:9.8(Critical)

I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

CWE-782017
CVSS:9.8(Critical)

A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

CVSS:9.8(Critical)

A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

CVSS:9.8(Critical)

nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

CWE-202017
CVSS:9.8(Critical)

soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution

CWE-782017
CVSS:9.8(Critical)

npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user

CWE-782017
CVSS:9.8(Critical)

LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.

CVSS:9.8(Critical)

ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution

CWE-782017
CVSS:9.8(Critical)

Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are then...