High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.3
High
Max CVSS
10.0
Highest
Min CVSS
7.2
Lowest

Browse by Severity

High Severity CVEs

Page 4639 of 4645
CVSS:7.5(High)

AAA authentication on Cisco systems allows attackers to execute commands without authorization.

CVSS:7.5(High)

The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.

CVSS:10.0(Critical)

In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.

CVSS:10.0(Critical)

Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.

CVSS:7.5(High)

Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.

CVSS:10.0(Critical)

The Java Web Server would allow remote users to obtain the source code for CGI programs.

CVSS:7.5(High)

Remote command execution in Microsoft Internet Explorer using .lnk and .url files.

CVSS:7.5(High)

Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.

CVSS:10.0(Critical)

MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.

CVSS:7.5(High)

Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

CVSS:10.0(Critical)

A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.

CVSS:7.5(High)

IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.

CVSS:10.0(Critical)

A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.