CSV
14,794 results for "vulnerability" Page 116
CVE-2019-2729 CRITICAL Exploit

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jun 19, 2019 19 affected product(s) NVD
9.8
CVSS
88.8%
EPSS
⚡ 75.8
CVE-2019-1620 CRITICAL Exploit

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this vulnerability by uploading specially crafted data to the affected device. A successful exploit could allow the attacker to write arbitrary files on the filesystem and execute code with root privileges on the affected device.

Jun 27, 2019 1 affected product(s) NVD
9.8
CVSS
83.8%
EPSS
⚡ 74.3
CVE-2019-1619 CRITICAL Exploit

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.

Jun 27, 2019 1 affected product(s) NVD
9.8
CVSS
82.8%
EPSS
⚡ 74
CVE-2019-7839 CRITICAL

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 12, 2019 34 affected product(s) NVD
9.8
CVSS
44.1%
EPSS
⚡ 52.4
CVE-2019-13375 CRITICAL

A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.

Jul 6, 2019 1 affected product(s) NVD
9.8
CVSS
28.2%
EPSS
⚡ 47.7
CVE-2019-13294 CRITICAL

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

Jul 4, 2019 1 affected product(s) NVD
9.8
CVSS
18.8%
EPSS
⚡ 44.8
CVE-2019-7838 CRITICAL

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 12, 2019 34 affected product(s) NVD
9.8
CVSS
17.4%
EPSS
⚡ 44.4
CVE-2019-7840 CRITICAL

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 12, 2019 34 affected product(s) NVD
9.8
CVSS
17.2%
EPSS
⚡ 44.4
CVE-2019-10989 CRITICAL

In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. Note: A different vulnerability than CVE-2019-10991.

Jun 28, 2019 1 affected product(s) NVD
9.8
CVSS
8.6%
EPSS
⚡ 41.8
CVE-2018-18471 CRITICAL

/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.

Jun 19, 2019 1 affected product(s) NVD
9.8
CVSS
7.7%
EPSS
⚡ 41.5
CVE-2018-11801 CRITICAL

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.

Jun 11, 2019 1 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2018-15506 CRITICAL

In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running BubbleUPnP, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack the cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Jun 19, 2019 1 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2019-11991 CRITICAL

HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.

Jul 9, 2019 1 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2018-14495 CRITICAL

Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

Jul 10, 2019 1 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2018-14496 CRITICAL

Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

Jul 10, 2019 1 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2018-17148 CRITICAL

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

Jun 19, 2019 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2016-10760 CRITICAL

On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.

Jun 11, 2019 4 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2019-7321 CRITICAL

Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.

Jun 13, 2019 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-18406 CRITICAL

An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE vulnerability is blind since the response doesn't directly display a requested file, but rather returns it inside the name data field when the report is saved. An attacker is able to view restricted operating system files. This issue affects all types of users: administrators or normal users.

Jun 19, 2019 1 affected product(s) NVD
9.9
CVSS
2.0%
EPSS
⚡ 40.2
CVE-2018-14494 CRITICAL

Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or recent Vivotek hardware or firmware

Jul 10, 2019 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2