CSV
14,811 results for "vulnerability" Page 101
CVE-2019-0604 CRITICAL KEV Exploit

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

Mar 5, 2019 4 affected product(s) NVD
9.8
CVSS
99.8%
EPSS
⚡ 99.1
CVE-2019-1003030 CRITICAL KEV Exploit

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

Mar 8, 2019 2 affected product(s) NVD
9.9
CVSS
96.9%
EPSS
⚡ 98.7
CVE-2019-1003029 CRITICAL KEV Exploit

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

Mar 8, 2019 2 affected product(s) NVD
9.9
CVSS
73.9%
EPSS
⚡ 91.8
CVE-2018-19276 CRITICAL Exploit

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

Mar 21, 2019 3 affected product(s) NVD
9.8
CVSS
98.7%
EPSS
⚡ 78.8
CVE-2019-1663 CRITICAL Exploit

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.

Feb 28, 2019 3 affected product(s) NVD
9.8
CVSS
95.7%
EPSS
⚡ 77.9
CVE-2019-0626 CRITICAL

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

Mar 5, 2019 17 affected product(s) NVD
9.8
CVSS
68.3%
EPSS
⚡ 59.7
CVE-2019-6714 CRITICAL

An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user uploads a PostView.ascx file using the file manager utility, which is currently allowed. This results in remote code execution for an authenticated user.

Mar 21, 2019 1 affected product(s) NVD
9.8
CVSS
31.7%
EPSS
⚡ 48.7
CVE-2018-18492 CRITICAL

A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

Feb 28, 2019 18 affected product(s) NVD
9.8
CVSS
9.6%
EPSS
⚡ 42.1
CVE-2019-8271 CRITICAL

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.

Mar 8, 2019 4 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2019-8273 CRITICAL

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.

Mar 8, 2019 4 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2019-8274 CRITICAL

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.

Mar 8, 2019 4 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2019-9117 CRITICAL

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNetworkTomographySettings API function, as demonstrated by shell metacharacters in the tomography_ping_number field.

Mar 7, 2019 2 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2019-9118 CRITICAL

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNTPServerSettings API function, as demonstrated by shell metacharacters in the system_time_timezone field.

Mar 7, 2019 2 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2019-9119 CRITICAL

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetStaticRouteSettings API function, as demonstrated by shell metacharacters in the staticroute_list field.

Mar 7, 2019 2 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2019-9120 CRITICAL

An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetWLanACLSettings API function, as demonstrated by shell metacharacters in the wl(0).(0)_maclist field.

Mar 7, 2019 2 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2019-9762 CRITICAL

A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.

Mar 14, 2019 1 affected product(s) NVD
9.8
CVSS
6.0%
EPSS
⚡ 41
CVE-2018-18815 CRITICAL

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows unauthenticated users to bypass authorization checks for portions of the HTTP interface to the JasperReports Server. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

Mar 7, 2019 9 affected product(s) NVD
10.0
CVSS
3.1%
EPSS
⚡ 40.9
CVE-2019-1723 CRITICAL

A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to the affected system using this account. A successful exploit could allow the attacker to log in to the CSPC using the default account. For Cisco CSPC 2.7.x, Cisco fixed this vulnerability in Release 2.7.4.6. For Cisco CSPC 2.8.x, Cisco fixed this vulnerability in Release 2.8.1.2.

Mar 13, 2019 2 affected product(s) NVD
9.8
CVSS
5.8%
EPSS
⚡ 40.9
CVE-2019-3922 CRITICAL

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, unauthenticated attacker to /GponForm/fsetup_Form. An attacker can leverage this vulnerability to potentially execute arbitrary code.

Mar 5, 2019 1 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2018-18493 CRITICAL

A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

Feb 28, 2019 18 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7