CSV
14,794 results for "vulnerability" Page 126
CVE-2019-16928 CRITICAL KEV Exploit

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

Sep 27, 2019 6 affected product(s) NVD
9.8
CVSS
42.5%
EPSS
⚡ 81.9
CVE-2019-12630 CRITICAL

A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of casuser.

Oct 2, 2019 1 affected product(s) NVD
9.8
CVSS
65.8%
EPSS
⚡ 59
CVE-2019-5485 CRITICAL

NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

Sep 13, 2019 1 affected product(s) NVD
10.0
CVSS
59.8%
EPSS
⚡ 57.9
CVE-2019-16932 CRITICAL

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

Sep 30, 2019 1 affected product(s) NVD
10.0
CVSS
39.1%
EPSS
⚡ 51.7
CVE-2019-8074 CRITICAL

ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.

Sep 27, 2019 17 affected product(s) NVD
9.8
CVSS
18.9%
EPSS
⚡ 44.9
CVE-2019-8073 CRITICAL

ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.

Sep 27, 2019 17 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2019-5481 CRITICAL

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

Sep 16, 2019 23 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2019-11210 CRITICAL

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.

Sep 18, 2019 3 affected product(s) NVD
10.0
CVSS
3.7%
EPSS
⚡ 41.1
CVE-2019-1365 CRITICAL

An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.

Oct 10, 2019 16 affected product(s) NVD
9.9
CVSS
4.4%
EPSS
⚡ 40.9
CVE-2019-16335 CRITICAL

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

Sep 15, 2019 39 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7
CVE-2019-11211 CRITICAL

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.

Sep 18, 2019 3 affected product(s) NVD
9.9
CVSS
3.7%
EPSS
⚡ 40.7
CVE-2019-15751 CRITICAL

An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to the web root of the application.

Oct 7, 2019 1 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.5
CVE-2019-10431 CRITICAL

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.

Oct 1, 2019 1 affected product(s) NVD
9.9
CVSS
2.7%
EPSS
⚡ 40.4
CVE-2019-5067 CRITICAL

An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

Sep 18, 2019 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2019-13658 CRITICAL

CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

Oct 2, 2019 2 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2019-13550 CRITICAL

In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow remote code execution or cause a system crash.

Sep 18, 2019 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40.1
CVE-2019-1584 CRITICAL

A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint.

Oct 9, 2019 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40.1
CVE-2019-16868 CRITICAL

emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.

Sep 25, 2019 2 affected product(s) NVD
9.8
CVSS
2.6%
EPSS
⚡ 40
CVE-2019-16755 CRITICAL

BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.

Sep 26, 2019 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 40
CVE-2019-16378 CRITICAL

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.

Sep 17, 2019 9 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 39.9