CSV
14,855 results for "vulnerability" Page 100
CVE-2019-0604 CRITICAL KEV Exploit

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

Mar 5, 2019 4 affected product(s) NVD
9.8
CVSS
99.8%
EPSS
⚡ 99.1
CVE-2019-9194 CRITICAL Exploit

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

Feb 26, 2019 1 affected product(s) NVD
9.8
CVSS
96.7%
EPSS
⚡ 78.2
CVE-2019-1663 CRITICAL Exploit

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.

Feb 28, 2019 3 affected product(s) NVD
9.8
CVSS
95.7%
EPSS
⚡ 77.9
CVE-2019-0626 CRITICAL

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

Mar 5, 2019 17 affected product(s) NVD
9.8
CVSS
68.3%
EPSS
⚡ 59.7
CVE-2019-8341 CRITICAL

An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing

Feb 15, 2019 3 affected product(s) NVD
9.8
CVSS
44.8%
EPSS
⚡ 52.6
CVE-2019-8917 CRITICAL

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.

Feb 18, 2019 1 affected product(s) NVD
9.8
CVSS
36.4%
EPSS
⚡ 50.1
CVE-2019-8985 CRITICAL

On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.

Feb 21, 2019 2 affected product(s) NVD
9.8
CVSS
13.3%
EPSS
⚡ 43.2
CVE-2019-9021 CRITICAL

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.

Feb 22, 2019 10 affected product(s) NVD
9.8
CVSS
10.1%
EPSS
⚡ 42.2
CVE-2018-18492 CRITICAL

A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

Feb 28, 2019 18 affected product(s) NVD
9.8
CVSS
9.6%
EPSS
⚡ 42.1
CVE-2019-9184 CRITICAL

SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

Feb 26, 2019 1 affected product(s) NVD
9.8
CVSS
9.0%
EPSS
⚡ 41.9
CVE-2019-8395 CRITICAL

An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.

Feb 17, 2019 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2019-9117 CRITICAL

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNetworkTomographySettings API function, as demonstrated by shell metacharacters in the tomography_ping_number field.

Mar 7, 2019 2 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2019-9118 CRITICAL

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNTPServerSettings API function, as demonstrated by shell metacharacters in the system_time_timezone field.

Mar 7, 2019 2 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2018-18815 CRITICAL

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows unauthenticated users to bypass authorization checks for portions of the HTTP interface to the JasperReports Server. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

Mar 7, 2019 9 affected product(s) NVD
10.0
CVSS
3.1%
EPSS
⚡ 40.9
CVE-2019-3922 CRITICAL

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, unauthenticated attacker to /GponForm/fsetup_Form. An attacker can leverage this vulnerability to potentially execute arbitrary code.

Mar 5, 2019 1 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2018-18493 CRITICAL

A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

Feb 28, 2019 18 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7
CVE-2018-20122 CRITICAL

The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges. No authentication is required in order to trigger the vulnerability.

Feb 21, 2019 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-8258 CRITICAL

UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.

Mar 5, 2019 4 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2018-18498 CRITICAL

A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

Feb 28, 2019 18 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2018-20033 CRITICAL

A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.

Feb 25, 2019 2 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3