CSV
14,794 results for "vulnerability" Page 115
CVE-2019-2729 CRITICAL Exploit

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jun 19, 2019 19 affected product(s) NVD
9.8
CVSS
88.8%
EPSS
⚡ 75.8
CVE-2019-12196 CRITICAL

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

Jun 5, 2019 1 affected product(s) NVD
9.8
CVSS
69.1%
EPSS
⚡ 59.9
CVE-2019-7839 CRITICAL

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 12, 2019 34 affected product(s) NVD
9.8
CVSS
44.1%
EPSS
⚡ 52.4
CVE-2019-8385 CRITICAL

An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677. Additionally, this could allow for privilege escalation by dumping the affected machine's SAM and SYSTEM database files, as well as remote code execution.

Jun 5, 2019 2 affected product(s) NVD
9.8
CVSS
19.6%
EPSS
⚡ 45.1
CVE-2019-7838 CRITICAL

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 12, 2019 34 affected product(s) NVD
9.8
CVSS
17.4%
EPSS
⚡ 44.4
CVE-2019-7840 CRITICAL

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 12, 2019 34 affected product(s) NVD
9.8
CVSS
17.2%
EPSS
⚡ 44.4
CVE-2019-5356 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
10.9%
EPSS
⚡ 42.5
CVE-2019-5352 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2019-5358 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2019-5367 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.0%
EPSS
⚡ 41.6
CVE-2019-5387 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2019-11949 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2018-18471 CRITICAL

/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.

Jun 19, 2019 1 affected product(s) NVD
9.8
CVSS
7.7%
EPSS
⚡ 41.5
CVE-2018-11800 CRITICAL

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

Jun 11, 2019 1 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2018-11801 CRITICAL

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.

Jun 11, 2019 1 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2018-15506 CRITICAL

In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running BubbleUPnP, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack the cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Jun 19, 2019 1 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2019-5390 CRITICAL

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Jun 5, 2019 9 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2018-20353 CRITICAL

An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

Jun 10, 2019 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2018-20354 CRITICAL

An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

Jun 10, 2019 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2018-20355 CRITICAL

An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

Jun 10, 2019 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3