CSV
14,794 results for "vulnerability" Page 125
CVE-2019-5485 CRITICAL

NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

Sep 13, 2019 1 affected product(s) NVD
10.0
CVSS
59.8%
EPSS
⚡ 57.9
CVE-2019-1306 CRITICAL

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

Sep 11, 2019 3 affected product(s) NVD
9.8
CVSS
17.0%
EPSS
⚡ 44.3
CVE-2019-12643 CRITICAL

A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploit this vulnerability by submitting malicious HTTP requests to the targeted device. A successful exploit could allow the attacker to obtain the token-id of an authenticated user. This token-id could be used to bypass authentication and execute privileged actions through the interface of the REST API virtual service container on the affected Cisco IOS XE device. The REST API interface is not enabled by default and must be installed and activated separately on IOS XE devices. See the Details section for more information.

Aug 28, 2019 2 affected product(s) NVD
10.0
CVSS
5.3%
EPSS
⚡ 41.6
CVE-2019-15896 CRITICAL

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.

Sep 10, 2019 1 affected product(s) NVD
9.8
CVSS
7.5%
EPSS
⚡ 41.4
CVE-2019-5481 CRITICAL

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

Sep 16, 2019 23 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2016-7398 CRITICAL

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Sep 6, 2019 10 affected product(s) NVD
9.8
CVSS
6.8%
EPSS
⚡ 41.2
CVE-2019-8070 CRITICAL

Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

Sep 12, 2019 4 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2019-11210 CRITICAL

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.

Sep 18, 2019 3 affected product(s) NVD
10.0
CVSS
3.7%
EPSS
⚡ 41.1
CVE-2018-7081 CRITICAL

A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute arbitrary code within the underlying operating system with full system privileges. Such an attack could lead to complete system compromise. The ability to transmit traffic to an IP interface on the mobility controller is required to carry out an attack. The attack leverages the PAPI protocol (UDP port 8211). If the mobility controller is only bridging L2 traffic to an uplink and does not have an IP address that is accessible to the attacker, it cannot be attacked.

Sep 13, 2019 6 affected product(s) NVD
9.8
CVSS
5.9%
EPSS
⚡ 41
CVE-2019-13656 CRITICAL

An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.

Sep 6, 2019 3 affected product(s) NVD
9.8
CVSS
5.8%
EPSS
⚡ 40.9
CVE-2019-16335 CRITICAL

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

Sep 15, 2019 39 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7
CVE-2019-11211 CRITICAL

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.

Sep 18, 2019 3 affected product(s) NVD
9.9
CVSS
3.7%
EPSS
⚡ 40.7
CVE-2019-8069 CRITICAL

Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

Sep 12, 2019 4 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.6
CVE-2019-5067 CRITICAL

An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

Sep 18, 2019 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2019-13550 CRITICAL

In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow remote code execution or cause a system crash.

Sep 18, 2019 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40.1
CVE-2019-14222 CRITICAL

An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present in all default installations. An attacker could exploit this vulnerability by using the extracted private key and bundling it into a PKCS12. A successful exploit could allow the attacker to gain information about the target system (e.g., OS type, system file locations, Java version, Solr version, etc.) as well as the ability to launch further attacks by leveraging the access to Alfresco's Solr Web Admin Interface.

Sep 5, 2019 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-16868 CRITICAL

emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.

Sep 25, 2019 2 affected product(s) NVD
9.8
CVSS
2.6%
EPSS
⚡ 40
CVE-2019-13405 CRITICAL

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.

Aug 29, 2019 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 39.9
CVE-2019-16378 CRITICAL

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.

Sep 17, 2019 9 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 39.9
CVE-2019-5066 CRITICAL

An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a use-after-free condition. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

Sep 18, 2019 1 affected product(s) NVD
9.8
CVSS
2.4%
EPSS
⚡ 39.9