CSV
14,794 results for "vulnerability" Page 131
CVE-2019-5029 CRITICAL

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

Nov 13, 2019 1 affected product(s) NVD
9.8
CVSS
57.2%
EPSS
⚡ 56.3
CVE-2019-1373 CRITICAL

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.

Nov 12, 2019 5 affected product(s) NVD
9.8
CVSS
18.2%
EPSS
⚡ 44.6
CVE-2019-14901 CRITICAL

A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.

Nov 29, 2019 13 affected product(s) NVD
9.8
CVSS
16.9%
EPSS
⚡ 44.3
CVE-2019-18655 CRITICAL

File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability. An unauthenticated attacker is able to perform remote command execution and obtain a command shell by sending a HTTP GET request including the malicious payload in the URL. A similar issue to CVE-2019-17415, CVE-2019-16724, and CVE-2010-2331.

Nov 12, 2019 1 affected product(s) NVD
9.8
CVSS
14.7%
EPSS
⚡ 43.6
CVE-2019-12419 CRITICAL

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

Nov 6, 2019 7 affected product(s) NVD
9.8
CVSS
13.8%
EPSS
⚡ 43.4
CVE-2019-14896 CRITICAL

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.

Nov 27, 2019 14 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2019-18580 CRITICAL

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

Nov 26, 2019 1 affected product(s) NVD
10.0
CVSS
4.9%
EPSS
⚡ 41.5
CVE-2019-1384 CRITICAL

A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.

Nov 12, 2019 18 affected product(s) NVD
9.9
CVSS
6.1%
EPSS
⚡ 41.4
CVE-2019-1449 CRITICAL

A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead to a standard user, any AppContainer sandbox, and Office LPAC Protected View to escalate privileges to SYSTEM.To exploit this bug, an attacker would have to run a specially crafted file, aka 'Microsoft Office ClickToRun Security Feature Bypass Vulnerability'.

Nov 12, 2019 2 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2019-14678 CRITICAL

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

Nov 14, 2019 2 affected product(s) NVD
10.0
CVSS
3.0%
EPSS
⚡ 40.9
CVE-2019-8246 CRITICAL

Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

Nov 14, 2019 1 affected product(s) NVD
9.8
CVSS
4.6%
EPSS
⚡ 40.6
CVE-2019-8247 CRITICAL

Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

Nov 14, 2019 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2019-8248 CRITICAL

Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

Nov 14, 2019 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2011-1939 CRITICAL

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

Nov 26, 2019 4 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2013-3073 CRITICAL

A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

Nov 14, 2019 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2019-15958 CRITICAL

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA) configuration and registration process of an affected device. An attacker could exploit this vulnerability by uploading a malicious file during the HA registration period. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system. Note: This vulnerability can only be exploited during the HA registration period. See the Details section for more information.

Nov 26, 2019 4 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2013-4654 CRITICAL

Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..

Nov 13, 2019 2 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2018-20687 CRITICAL

An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Nov 18, 2019 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 40
CVE-2013-2091 CRITICAL

SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

Nov 20, 2019 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 40
CVE-2019-8144 CRITICAL

A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.

Nov 6, 2019 4 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 39.9