CSV
14,783 results for "vulnerability" Page 136
CVE-2019-20361 CRITICAL Exploit

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

Jan 8, 2020 1 affected product(s) NVD
9.8
CVSS
85.1%
EPSS
⚡ 74.7
CVE-2014-8516 CRITICAL Exploit

Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

Jan 3, 2020 1 affected product(s) NVD
9.8
CVSS
81.7%
EPSS
⚡ 73.7
CVE-2019-16451 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 7 affected product(s) NVD
9.8
CVSS
34.7%
EPSS
⚡ 49.6
CVE-2019-17146 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the SOAPAction request header, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8458.

Jan 7, 2020 2 affected product(s) NVD
9.8
CVSS
9.5%
EPSS
⚡ 42.1
CVE-2019-11994 CRITICAL

A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. An API is used to execute a command manifest file during upgrade does not correctly prevent directory traversal and so can be used to execute manifest files in arbitrary locations on the node. The API does not require user authentication and is accessible over the management network, resulting in the potential for unauthenticated remote execution of manifest files. For all customers running HPE OmniStack version 3.7.9 and earlier. HPE recommends upgrading the OmniStack software to version 3.7.10 or later, which contains a permanent resolution. Customers and partners who can upgrade to 3.7.10 should upgrade at the earliest convenience. For all customers and partners unable to upgrade their environments to the recommended version 3.7.10, HPE has created a Temporary Workaround https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=mmr_sf-EN_US000061901&withFrame for you to implement. All customer should upgrade to the recommended 3.7.10 or later version at the earliest convenience.

Jan 3, 2020 8 affected product(s) NVD
9.8
CVSS
7.2%
EPSS
⚡ 41.4
CVE-2020-6170 CRITICAL

An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

Jan 8, 2020 1 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2019-8255 CRITICAL

Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 19, 2019 1 affected product(s) NVD
9.8
CVSS
6.6%
EPSS
⚡ 41.2
CVE-2019-16452 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.1
CVE-2019-16453 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
6.0%
EPSS
⚡ 41
CVE-2019-16463 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2019-7489 CRITICAL

A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.

Dec 23, 2019 1 affected product(s) NVD
9.8
CVSS
5.3%
EPSS
⚡ 40.8
CVE-2019-16455 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-16459 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-16460 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-16462 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-16464 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-10774 CRITICAL

php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 30, 2019 1 affected product(s) NVD
9.8
CVSS
4.6%
EPSS
⚡ 40.6
CVE-2014-8337 CRITICAL

Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.

Jan 3, 2020 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-16454 CRITICAL

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

Dec 19, 2019 6 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2018-10388 CRITICAL

Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

Dec 23, 2019 1 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5