CSV
14,794 results for "vulnerability" Page 132
CVE-2019-18935 CRITICAL KEV Exploit

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

Dec 11, 2019 1 affected product(s) NVD
9.8
CVSS
99.7%
EPSS
⚡ 99.1
CVE-2019-7195 CRITICAL KEV Exploit

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

Dec 5, 2019 4 affected product(s) NVD
9.8
CVSS
89.7%
EPSS
⚡ 96.1
CVE-2019-7192 CRITICAL KEV Exploit

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

Dec 5, 2019 4 affected product(s) NVD
9.8
CVSS
88.2%
EPSS
⚡ 95.7
CVE-2019-7194 CRITICAL KEV Exploit

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

Dec 5, 2019 4 affected product(s) NVD
9.8
CVSS
83.1%
EPSS
⚡ 94.1
CVE-2019-7193 CRITICAL KEV Exploit

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Dec 5, 2019 16 affected product(s) NVD
9.8
CVSS
14.4%
EPSS
⚡ 73.5
CVE-2019-5096 CRITICAL

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.

Dec 3, 2019 3 affected product(s) NVD
9.8
CVSS
67.0%
EPSS
⚡ 59.3
CVE-2019-12518 CRITICAL

Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.

Dec 2, 2019 2 affected product(s) NVD
9.8
CVSS
50.7%
EPSS
⚡ 54.4
CVE-2019-14901 CRITICAL

A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.

Nov 29, 2019 13 affected product(s) NVD
9.8
CVSS
16.9%
EPSS
⚡ 44.3
CVE-2019-14896 CRITICAL

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.

Nov 27, 2019 14 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2019-18580 CRITICAL

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

Nov 26, 2019 1 affected product(s) NVD
10.0
CVSS
4.9%
EPSS
⚡ 41.5
CVE-2019-14678 CRITICAL

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

Nov 14, 2019 2 affected product(s) NVD
10.0
CVSS
3.0%
EPSS
⚡ 40.9
CVE-2019-8248 CRITICAL

Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

Nov 14, 2019 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2011-1939 CRITICAL

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

Nov 26, 2019 4 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2013-3073 CRITICAL

A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

Nov 14, 2019 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2019-19230 CRITICAL

An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.

Dec 9, 2019 1 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2019-15958 CRITICAL

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA) configuration and registration process of an affected device. An attacker could exploit this vulnerability by uploading a malicious file during the HA registration period. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system. Note: This vulnerability can only be exploited during the HA registration period. See the Details section for more information.

Nov 26, 2019 4 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2019-18671 CRITICAL

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.

Dec 6, 2019 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2019-5085 CRITICAL

An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an integer overflow, resulting in heap corruption. An attacker can send a packet to trigger this vulnerability.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2018-20687 CRITICAL

An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Nov 18, 2019 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 40
CVE-2013-2091 CRITICAL

SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

Nov 20, 2019 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 40