CSV
14,784 results for "vulnerability" Page 138
CVE-2020-0646 CRITICAL KEV Exploit

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

Jan 14, 2020 28 affected product(s) NVD
9.8
CVSS
99.2%
EPSS
⚡ 99
CVE-2020-2555 CRITICAL KEV Exploit

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jan 15, 2020 22 affected product(s) NVD
9.8
CVSS
97.1%
EPSS
⚡ 98.3
CVE-2020-2551 CRITICAL KEV Exploit

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jan 15, 2020 4 affected product(s) NVD
9.8
CVSS
93.2%
EPSS
⚡ 97.2
CVE-2020-0609 CRITICAL Exploit

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

Jan 14, 2020 4 affected product(s) NVD
9.8
CVSS
74.9%
EPSS
⚡ 71.7
CVE-2012-4284 CRITICAL

A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code

Jan 10, 2020 1 affected product(s) NVD
9.8
CVSS
69.5%
EPSS
⚡ 60.1
CVE-2020-0610 CRITICAL

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.

Jan 14, 2020 4 affected product(s) NVD
9.8
CVSS
67.6%
EPSS
⚡ 59.5
CVE-2014-5007 CRITICAL

Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.

Jan 17, 2020 2 affected product(s) NVD
9.8
CVSS
37.3%
EPSS
⚡ 50.4
CVE-2013-6225 CRITICAL

LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability

Jan 13, 2020 1 affected product(s) NVD
9.8
CVSS
26.6%
EPSS
⚡ 47.2
CVE-2013-1592 CRITICAL

A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code.

Jan 23, 2020 4 affected product(s) NVD
9.8
CVSS
24.4%
EPSS
⚡ 46.5
CVE-2012-4750 CRITICAL

A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service

Jan 13, 2020 1 affected product(s) NVD
9.8
CVSS
8.9%
EPSS
⚡ 41.9
CVE-2020-6962 CRITICAL

In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an attacker to obtain arbitrary remote code execution.

Jan 24, 2020 17 affected product(s) NVD
10.0
CVSS
4.9%
EPSS
⚡ 41.5
CVE-2009-1120 CRITICAL

EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists within the DoRcvRpcCall RPC function -exposed via the rep_srv.exe process- where the vulnerability is caused by an error when the rep_srv.exe handles a specially crafted packet sent by an unauthenticated attacker.

Jan 15, 2020 1 affected product(s) NVD
9.8
CVSS
7.4%
EPSS
⚡ 41.4
CVE-2020-2546 CRITICAL

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jan 15, 2020 2 affected product(s) NVD
9.8
CVSS
5.1%
EPSS
⚡ 40.7
CVE-2012-5190 CRITICAL

Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability

Jan 21, 2020 1 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2020-6961 CRITICAL

In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.

Jan 24, 2020 9 affected product(s) NVD
10.0
CVSS
1.6%
EPSS
⚡ 40.5
CVE-2015-5952 CRITICAL

Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.

Jan 15, 2020 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2015-5334 CRITICAL

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.

Jan 23, 2020 2 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.2
CVE-2020-2586 CRITICAL

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Human Resources. While the vulnerability is in Oracle Human Resources, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Human Resources. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).

Jan 15, 2020 2 affected product(s) NVD
9.9
CVSS
1.5%
EPSS
⚡ 40.1
CVE-2020-2587 CRITICAL

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Human Resources. While the vulnerability is in Oracle Human Resources, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Human Resources. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).

Jan 15, 2020 2 affected product(s) NVD
9.9
CVSS
1.5%
EPSS
⚡ 40.1
CVE-2012-4919 CRITICAL

Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

Jan 22, 2020 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1