CSV
14,794 results for "vulnerability" Page 108
CVE-2019-11510 CRITICAL KEV Exploit

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

May 8, 2019 37 affected product(s) NVD
10.0
CVSS
100.0%
EPSS
⚡ 100
CVE-2019-0708 CRITICAL KEV Exploit

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

May 16, 2019 75 affected product(s) NVD
9.8
CVSS
100.0%
EPSS
⚡ 99.2
CVE-2019-3568 CRITICAL KEV Exploit

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

May 14, 2019 6 affected product(s) NVD
9.8
CVSS
39.2%
EPSS
⚡ 80.9
CVE-2018-19986 CRITICAL

In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the $path_inf_wan1."/web" internal configuration memory without any regex checking. And in the IPTWAN_build_command function of the iptwan.php source code, the data in $path_inf_wan1."/web" is used with the iptables command without any regex checking. A vulnerable /HNAP1/SetRouterSettings XML message could have shell metacharacters in the RemotePort element such as the `telnetd` string.

May 13, 2019 2 affected product(s) NVD
9.8
CVSS
41.6%
EPSS
⚡ 51.7
CVE-2019-7442 CRITICAL

An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.

May 8, 2019 1 affected product(s) NVD
9.8
CVSS
40.0%
EPSS
⚡ 51.2
CVE-2019-1867 CRITICAL

A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.

May 10, 2019 1 affected product(s) NVD
10.0
CVSS
30.3%
EPSS
⚡ 49.1
CVE-2019-0725 CRITICAL

A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

May 16, 2019 8 affected product(s) NVD
9.8
CVSS
26.3%
EPSS
⚡ 47.1
CVE-2019-7762 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2019-7763 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2019-7764 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.6%
EPSS
⚡ 41.2
CVE-2019-7765 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2019-7766 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.6%
EPSS
⚡ 41.2
CVE-2019-7767 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2019-7772 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2019-7779 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.6%
EPSS
⚡ 41.2
CVE-2019-7781 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2019-7783 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

May 22, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2019-5021 CRITICAL

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

May 8, 2019 4 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2018-19989 CRITICAL

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwc_tc_spq_start, bwc_tc_wfq_start, and bwc_tc_adb_start functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the `telnetd` string.

May 13, 2019 2 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.9
CVE-2018-15128 CRITICAL

An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buffer Overflow via crafted packets.

May 13, 2019 3 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8