Critical Severity Vulnerabilities

28.6K CVEs classified as critical severity

CRITICAL
Total CVEs
28.6K
Vulnerabilities
Avg CVSS
9.8
Critical
Max CVSS
9.8
Highest
Min CVSS
9.8
Lowest

Browse by Severity

Critical Severity CVEs

Page 960 of 1190
CVSS:9.8(Critical)

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on ...

CVSS:9.8(Critical)

The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

CVSS:9.8(Critical)

The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.

CWE-202016
CVSS:9.8(Critical)

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers...

CVSS:9.8(Critical)

The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.

CVSS:9.8(Critical)

The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.

CVSS:9.8(Critical)

The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.

CWE-892016
CVSS:9.8(Critical)

The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.

CWE-892016
CVSS:9.8(Critical)

The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.

CWE-892016
CVSS:9.8(Critical)

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on ...

CVSS:9.8(Critical)

The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.

CWE-892016
CVSS:9.8(Critical)

The olimometer plugin before 2.57 for WordPress has SQL injection.

CWE-892016
CVSS:9.8(Critical)

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on ...

CVSS:9.8(Critical)

The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.

CWE-892016
CVSS:9.8(Critical)

The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.

CWE-892016
CVSS:9.8(Critical)

The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.

CWE-892016
CVSS:9.8(Critical)

The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.

CVSS:9.8(Critical)

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers...

CVSS:9.8(Critical)

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers...

CVSS:9.8(Critical)

cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

CWE-202016
CVSS:9.8(Critical)

cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

CWE-202016
CVSS:9.8(Critical)

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers...

CVSS:9.8(Critical)

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers...

CVSS:9.8(Critical)

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers...