CSV
14,794 results for "vulnerability" Page 127
CVE-2019-16928 CRITICAL KEV Exploit

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

Sep 27, 2019 6 affected product(s) NVD
9.8
CVSS
42.5%
EPSS
⚡ 81.9
CVE-2019-17662 CRITICAL Exploit

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

Oct 16, 2019 1 affected product(s) NVD
9.8
CVSS
96.8%
EPSS
⚡ 78.2
CVE-2019-17602 CRITICAL Exploit

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.

Oct 15, 2019 41 affected product(s) NVD
9.8
CVSS
81.5%
EPSS
⚡ 73.7
CVE-2019-12630 CRITICAL

A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of casuser.

Oct 2, 2019 1 affected product(s) NVD
9.8
CVSS
65.8%
EPSS
⚡ 59
CVE-2019-16932 CRITICAL

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

Sep 30, 2019 1 affected product(s) NVD
10.0
CVSS
39.1%
EPSS
⚡ 51.7
CVE-2019-8195 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
22.9%
EPSS
⚡ 46.1
CVE-2019-1372 CRITICAL

An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.

Oct 10, 2019 1 affected product(s) NVD
10.0
CVSS
19.0%
EPSS
⚡ 45.7
CVE-2019-8074 CRITICAL

ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.

Sep 27, 2019 17 affected product(s) NVD
9.8
CVSS
18.9%
EPSS
⚡ 44.9
CVE-2019-2904 CRITICAL

Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 16, 2019 48 affected product(s) NVD
9.8
CVSS
14.3%
EPSS
⚡ 43.5
CVE-2019-8073 CRITICAL

ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.

Sep 27, 2019 17 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2019-17059 CRITICAL

A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.

Oct 11, 2019 7 affected product(s) NVD
9.8
CVSS
7.4%
EPSS
⚡ 41.4
CVE-2019-1365 CRITICAL

An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.

Oct 10, 2019 16 affected product(s) NVD
9.9
CVSS
4.4%
EPSS
⚡ 40.9
CVE-2019-17495 CRITICAL

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.

Oct 10, 2019 17 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2019-17669 CRITICAL

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

Oct 17, 2019 4 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2019-17670 CRITICAL

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

Oct 17, 2019 4 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.6
CVE-2019-15751 CRITICAL

An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to the web root of the application.

Oct 7, 2019 1 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.5
CVE-2019-8161 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-8167 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-8169 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-10431 CRITICAL

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.

Oct 1, 2019 1 affected product(s) NVD
9.9
CVSS
2.7%
EPSS
⚡ 40.4