CSV
14,794 results for "vulnerability" Page 114
CVE-2019-9670 CRITICAL KEV Exploit

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

May 29, 2019 11 affected product(s) NVD
9.8
CVSS
100.0%
EPSS
⚡ 99.2
CVE-2019-11580 CRITICAL KEV Exploit

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

Jun 3, 2019 5 affected product(s) NVD
9.8
CVSS
95.4%
EPSS
⚡ 97.8
CVE-2019-11945 CRITICAL Exploit

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
78.6%
EPSS
⚡ 72.8
CVE-2019-12196 CRITICAL

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

Jun 5, 2019 1 affected product(s) NVD
9.8
CVSS
69.1%
EPSS
⚡ 59.9
CVE-2019-8385 CRITICAL

An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677. Additionally, this could allow for privilege escalation by dumping the affected machine's SAM and SYSTEM database files, as well as remote code execution.

Jun 5, 2019 2 affected product(s) NVD
9.8
CVSS
19.6%
EPSS
⚡ 45.1
CVE-2019-11944 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
13.3%
EPSS
⚡ 43.2
CVE-2019-5356 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
10.9%
EPSS
⚡ 42.5
CVE-2019-7095 CRITICAL

Adobe Digital Editions versions 4.5.10.185749 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

May 24, 2019 1 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2018-7124 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.0%
EPSS
⚡ 41.6
CVE-2019-5352 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2019-5358 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2019-5367 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.0%
EPSS
⚡ 41.6
CVE-2019-5387 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2019-11949 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2018-7121 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
7.6%
EPSS
⚡ 41.5
CVE-2019-6742 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the GameServiceReceiver update mechanism. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7477.

Jun 3, 2019 1 affected product(s) NVD
9.8
CVSS
5.9%
EPSS
⚡ 41
CVE-2019-5347 CRITICAL

A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2018-11800 CRITICAL

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

Jun 11, 2019 1 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2019-11185 CRITICAL

The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with a whitelisted file extension, and prepending "magic bytes" to the payload to pass MIME checks. Specifically, an unauthenticated remote user submits a crafted file upload POST request to the REST api remote_upload endpoint. The file contains data that will fool the plugin's MIME check into classifying it as an image (which is a whitelisted file extension) and finally a trailing .phtml file extension.

Jun 3, 2019 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2019-5390 CRITICAL

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5