CSV
14,794 results for "vulnerability" Page 128
CVE-2019-17662 CRITICAL Exploit

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

Oct 16, 2019 1 affected product(s) NVD
9.8
CVSS
96.8%
EPSS
⚡ 78.2
CVE-2019-17602 CRITICAL Exploit

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.

Oct 15, 2019 41 affected product(s) NVD
9.8
CVSS
81.5%
EPSS
⚡ 73.7
CVE-2019-18370 CRITICAL

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.

Oct 23, 2019 1 affected product(s) NVD
9.8
CVSS
40.3%
EPSS
⚡ 51.3
CVE-2019-18394 CRITICAL

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

Oct 24, 2019 1 affected product(s) NVD
9.8
CVSS
32.3%
EPSS
⚡ 48.9
CVE-2019-8195 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
22.9%
EPSS
⚡ 46.1
CVE-2019-8196 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
22.9%
EPSS
⚡ 46.1
CVE-2019-1372 CRITICAL

An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.

Oct 10, 2019 1 affected product(s) NVD
10.0
CVSS
19.0%
EPSS
⚡ 45.7
CVE-2019-8197 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
16.8%
EPSS
⚡ 44.3
CVE-2019-2904 CRITICAL

Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 16, 2019 48 affected product(s) NVD
9.8
CVSS
14.3%
EPSS
⚡ 43.5
CVE-2019-17059 CRITICAL

A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.

Oct 11, 2019 7 affected product(s) NVD
9.8
CVSS
7.4%
EPSS
⚡ 41.4
CVE-2019-17495 CRITICAL

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.

Oct 10, 2019 17 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2019-17669 CRITICAL

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

Oct 17, 2019 4 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2019-17670 CRITICAL

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

Oct 17, 2019 4 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.6
CVE-2019-8161 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-8167 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-8169 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-8199 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2019-8200 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-8186 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.4
CVE-2019-8205 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4