CSV
14,784 results for "vulnerability" Page 141
CVE-2014-8739 CRITICAL Exploit

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

Feb 8, 2020 3 affected product(s) NVD
9.8
CVSS
91.7%
EPSS
⚡ 76.7
CVE-2013-1359 CRITICAL Exploit

An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.

Feb 11, 2020 12 affected product(s) NVD
9.8
CVSS
89.4%
EPSS
⚡ 76
CVE-2013-3214 CRITICAL Exploit

vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

Jan 28, 2020 1 affected product(s) NVD
9.8
CVSS
84.5%
EPSS
⚡ 74.6
CVE-2013-0803 CRITICAL Exploit

A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.

Feb 11, 2020 1 affected product(s) NVD
9.8
CVSS
75.0%
EPSS
⚡ 71.7
CVE-2013-2010 CRITICAL Exploit

WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

Feb 12, 2020 2 affected product(s) NVD
9.8
CVSS
73.9%
EPSS
⚡ 71.4
CVE-2013-3215 CRITICAL

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

Jan 29, 2020 1 affected product(s) NVD
9.8
CVSS
68.8%
EPSS
⚡ 59.9
CVE-2013-2568 CRITICAL

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

Jan 29, 2020 2 affected product(s) NVD
9.8
CVSS
48.5%
EPSS
⚡ 53.8
CVE-2013-2573 CRITICAL

A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.

Jan 29, 2020 3 affected product(s) NVD
9.8
CVSS
42.2%
EPSS
⚡ 51.9
CVE-2013-1599 CRITICAL

A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.

Jan 28, 2020 19 affected product(s) NVD
9.8
CVSS
40.4%
EPSS
⚡ 51.3
CVE-2013-2570 CRITICAL

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.

Jan 29, 2020 2 affected product(s) NVD
9.8
CVSS
26.6%
EPSS
⚡ 47.2
CVE-2013-1360 CRITICAL

An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.

Feb 11, 2020 12 affected product(s) NVD
9.8
CVSS
23.2%
EPSS
⚡ 46.2
CVE-2014-5091 CRITICAL

A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.

Feb 7, 2020 1 affected product(s) NVD
9.8
CVSS
15.2%
EPSS
⚡ 43.7
CVE-2020-3716 CRITICAL

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 29, 2020 6 affected product(s) NVD
9.8
CVSS
14.0%
EPSS
⚡ 43.4
CVE-2013-6236 CRITICAL

IZON IP 2.0.2: hard-coded password vulnerability

Feb 12, 2020 1 affected product(s) NVD
9.8
CVSS
10.2%
EPSS
⚡ 42.3
CVE-2013-2681 CRITICAL

Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

Feb 5, 2020 1 affected product(s) NVD
9.8
CVSS
10.1%
EPSS
⚡ 42.2
CVE-2020-3718 CRITICAL

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 29, 2020 6 affected product(s) NVD
9.8
CVSS
7.5%
EPSS
⚡ 41.5
CVE-2014-5087 CRITICAL

A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.

Feb 7, 2020 3 affected product(s) NVD
9.8
CVSS
7.2%
EPSS
⚡ 41.4
CVE-2011-3642 CRITICAL

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

Feb 8, 2020 2 affected product(s) NVD
9.6
CVSS
8.8%
EPSS
⚡ 41
CVE-2020-3742 CRITICAL

Adobe Acrobat and Reader versions, 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
5.8%
EPSS
⚡ 40.9
CVE-2020-3740 CRITICAL

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Feb 13, 2020 1 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7