High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.1
High
Max CVSS
10.0
Highest
Min CVSS
7.2
Lowest

Browse by Severity

High Severity CVEs

Page 4634 of 4645
CVSS:10.0(Critical)

Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.

CWE-941999
CVSS:7.5(High)

An account on a router, firewall, or other network device has a guessable password.

CVSS:7.2(High)

A Windows NT domain user or administrator account has a default, null, blank, or missing password.

CVSS:7.5(High)

A Windows NT local user or administrator account has a default, null, blank, or missing password.

CVSS:10.0(Critical)

TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.

CVSS:7.2(High)

A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.

CVSS:10.0(Critical)

A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.

CVSS:7.5(High)

rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automo...

CVSS:10.0(Critical)

The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.

CVSS:7.5(High)

MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.

CVSS:10.0(Critical)

MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.

CVSS:7.5(High)

Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.

CVSS:7.5(High)

The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

CVSS:7.2(High)

A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.

CVSS:7.2(High)

The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.

CVSS:10.0(Critical)

Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

CVSS:7.2(High)

suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy d...

CVSS:10.0(Critical)

Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.