CSV
14,784 results for "vulnerability" Page 140
CVE-2013-3214 CRITICAL Exploit

vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

Jan 28, 2020 1 affected product(s) NVD
9.8
CVSS
84.5%
EPSS
⚡ 74.6
CVE-2014-8741 CRITICAL Exploit

Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.

Jan 27, 2020 1 affected product(s) NVD
9.8
CVSS
77.2%
EPSS
⚡ 72.4
CVE-2013-7390 CRITICAL Exploit

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.

Jan 27, 2020 1 affected product(s) NVD
9.8
CVSS
74.5%
EPSS
⚡ 71.6
CVE-2013-3215 CRITICAL

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

Jan 29, 2020 1 affected product(s) NVD
9.8
CVSS
68.8%
EPSS
⚡ 59.9
CVE-2013-2568 CRITICAL

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

Jan 29, 2020 2 affected product(s) NVD
9.8
CVSS
48.5%
EPSS
⚡ 53.8
CVE-2013-2573 CRITICAL

A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.

Jan 29, 2020 3 affected product(s) NVD
9.8
CVSS
42.2%
EPSS
⚡ 51.9
CVE-2013-1595 CRITICAL

A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service.

Jan 24, 2020 2 affected product(s) NVD
9.8
CVSS
41.6%
EPSS
⚡ 51.7
CVE-2013-1599 CRITICAL

A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.

Jan 28, 2020 19 affected product(s) NVD
9.8
CVSS
40.4%
EPSS
⚡ 51.3
CVE-2013-2570 CRITICAL

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.

Jan 29, 2020 2 affected product(s) NVD
9.8
CVSS
26.6%
EPSS
⚡ 47.2
CVE-2020-3716 CRITICAL

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 29, 2020 6 affected product(s) NVD
9.8
CVSS
14.0%
EPSS
⚡ 43.4
CVE-2013-2681 CRITICAL

Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

Feb 5, 2020 1 affected product(s) NVD
9.8
CVSS
10.1%
EPSS
⚡ 42.2
CVE-2020-3718 CRITICAL

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 29, 2020 6 affected product(s) NVD
9.8
CVSS
7.5%
EPSS
⚡ 41.5
CVE-2014-5087 CRITICAL

A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.

Feb 7, 2020 3 affected product(s) NVD
9.8
CVSS
7.2%
EPSS
⚡ 41.4
CVE-2014-4172 CRITICAL

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.

Jan 24, 2020 5 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2019-7131 CRITICAL

Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2019.010.20064 and earlier, 2017.011.30110 and earlier version, and 2015.006.30461 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 28, 2020 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2011-1517 CRITICAL

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

Feb 5, 2020 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2019-8257 CRITICAL

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Jan 28, 2020 6 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2014-2025 CRITICAL

Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.

Jan 31, 2020 2 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2013-4521 CRITICAL

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

Feb 6, 2020 28 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2013-2612 CRITICAL

Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI.

Jan 27, 2020 1 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1