CSV
14,783 results for "vulnerability" Page 137
CVE-2020-0646 CRITICAL KEV Exploit

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

Jan 14, 2020 28 affected product(s) NVD
9.8
CVSS
99.2%
EPSS
⚡ 99
CVE-2020-2555 CRITICAL KEV Exploit

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jan 15, 2020 22 affected product(s) NVD
9.8
CVSS
97.1%
EPSS
⚡ 98.3
CVE-2020-2551 CRITICAL KEV Exploit

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jan 15, 2020 4 affected product(s) NVD
9.8
CVSS
93.2%
EPSS
⚡ 97.2
CVE-2019-20361 CRITICAL Exploit

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

Jan 8, 2020 1 affected product(s) NVD
9.8
CVSS
85.1%
EPSS
⚡ 74.7
CVE-2014-8516 CRITICAL Exploit

Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

Jan 3, 2020 1 affected product(s) NVD
9.8
CVSS
81.7%
EPSS
⚡ 73.7
CVE-2020-0609 CRITICAL Exploit

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

Jan 14, 2020 4 affected product(s) NVD
9.8
CVSS
74.9%
EPSS
⚡ 71.7
CVE-2012-4284 CRITICAL

A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code

Jan 10, 2020 1 affected product(s) NVD
9.8
CVSS
69.5%
EPSS
⚡ 60.1
CVE-2020-0610 CRITICAL

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.

Jan 14, 2020 4 affected product(s) NVD
9.8
CVSS
67.6%
EPSS
⚡ 59.5
CVE-2013-6225 CRITICAL

LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability

Jan 13, 2020 1 affected product(s) NVD
9.8
CVSS
26.6%
EPSS
⚡ 47.2
CVE-2019-17146 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the SOAPAction request header, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8458.

Jan 7, 2020 2 affected product(s) NVD
9.8
CVSS
9.5%
EPSS
⚡ 42.1
CVE-2012-4750 CRITICAL

A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service

Jan 13, 2020 1 affected product(s) NVD
9.8
CVSS
8.9%
EPSS
⚡ 41.9
CVE-2019-11994 CRITICAL

A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. An API is used to execute a command manifest file during upgrade does not correctly prevent directory traversal and so can be used to execute manifest files in arbitrary locations on the node. The API does not require user authentication and is accessible over the management network, resulting in the potential for unauthenticated remote execution of manifest files. For all customers running HPE OmniStack version 3.7.9 and earlier. HPE recommends upgrading the OmniStack software to version 3.7.10 or later, which contains a permanent resolution. Customers and partners who can upgrade to 3.7.10 should upgrade at the earliest convenience. For all customers and partners unable to upgrade their environments to the recommended version 3.7.10, HPE has created a Temporary Workaround https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=mmr_sf-EN_US000061901&withFrame for you to implement. All customer should upgrade to the recommended 3.7.10 or later version at the earliest convenience.

Jan 3, 2020 8 affected product(s) NVD
9.8
CVSS
7.2%
EPSS
⚡ 41.4
CVE-2020-6170 CRITICAL

An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

Jan 8, 2020 1 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2009-1120 CRITICAL

EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists within the DoRcvRpcCall RPC function -exposed via the rep_srv.exe process- where the vulnerability is caused by an error when the rep_srv.exe handles a specially crafted packet sent by an unauthenticated attacker.

Jan 15, 2020 1 affected product(s) NVD
9.8
CVSS
7.4%
EPSS
⚡ 41.4
CVE-2020-2546 CRITICAL

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jan 15, 2020 2 affected product(s) NVD
9.8
CVSS
5.1%
EPSS
⚡ 40.7
CVE-2019-10774 CRITICAL

php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 30, 2019 1 affected product(s) NVD
9.8
CVSS
4.6%
EPSS
⚡ 40.6
CVE-2014-8337 CRITICAL

Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.

Jan 3, 2020 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2014-3448 CRITICAL

BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload

Jan 9, 2020 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2019-5082 CRITICAL

An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

Jan 8, 2020 3 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2015-5952 CRITICAL

Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.

Jan 15, 2020 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2