CSV
14,794 results for "vulnerability" Page 124
CVE-2019-14314 CRITICAL

A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

Aug 27, 2019 1 affected product(s) NVD
9.8
CVSS
43.4%
EPSS
⚡ 52.2
CVE-2019-1306 CRITICAL

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

Sep 11, 2019 3 affected product(s) NVD
9.8
CVSS
17.0%
EPSS
⚡ 44.3
CVE-2019-7990 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2019-7993 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2019-12643 CRITICAL

A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploit this vulnerability by submitting malicious HTTP requests to the targeted device. A successful exploit could allow the attacker to obtain the token-id of an authenticated user. This token-id could be used to bypass authentication and execute privileged actions through the interface of the REST API virtual service container on the affected Cisco IOS XE device. The REST API interface is not enabled by default and must be installed and activated separately on IOS XE devices. See the Details section for more information.

Aug 28, 2019 2 affected product(s) NVD
10.0
CVSS
5.3%
EPSS
⚡ 41.6
CVE-2019-7968 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2019-15896 CRITICAL

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.

Sep 10, 2019 1 affected product(s) NVD
9.8
CVSS
7.5%
EPSS
⚡ 41.4
CVE-2016-7398 CRITICAL

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Sep 6, 2019 10 affected product(s) NVD
9.8
CVSS
6.8%
EPSS
⚡ 41.2
CVE-2019-7969 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7970 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7971 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7972 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7973 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7974 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7975 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7997 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-7998 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-8001 CRITICAL

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 26, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-8070 CRITICAL

Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

Sep 12, 2019 4 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2018-7081 CRITICAL

A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute arbitrary code within the underlying operating system with full system privileges. Such an attack could lead to complete system compromise. The ability to transmit traffic to an IP interface on the mobility controller is required to carry out an attack. The attack leverages the PAPI protocol (UDP port 8211). If the mobility controller is only bridging L2 traffic to an uplink and does not have an IP address that is accessible to the attacker, it cannot be attacked.

Sep 13, 2019 6 affected product(s) NVD
9.8
CVSS
5.9%
EPSS
⚡ 41