CSV
14,784 results for "vulnerability" Page 142
CVE-2014-8739 CRITICAL Exploit

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

Feb 8, 2020 3 affected product(s) NVD
9.8
CVSS
91.7%
EPSS
⚡ 76.7
CVE-2013-1359 CRITICAL Exploit

An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.

Feb 11, 2020 12 affected product(s) NVD
9.8
CVSS
89.4%
EPSS
⚡ 76
CVE-2020-8012 CRITICAL Exploit

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

Feb 18, 2020 3 affected product(s) NVD
9.8
CVSS
77.4%
EPSS
⚡ 72.4
CVE-2013-0803 CRITICAL Exploit

A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.

Feb 11, 2020 1 affected product(s) NVD
9.8
CVSS
75.0%
EPSS
⚡ 71.7
CVE-2013-2010 CRITICAL Exploit

WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

Feb 12, 2020 2 affected product(s) NVD
9.8
CVSS
73.9%
EPSS
⚡ 71.4
CVE-2013-4211 CRITICAL Exploit

A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code

Feb 14, 2020 1 affected product(s) NVD
9.8
CVSS
70.7%
EPSS
⚡ 70.4
CVE-2020-8010 CRITICAL

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

Feb 18, 2020 3 affected product(s) NVD
9.8
CVSS
48.7%
EPSS
⚡ 53.8
CVE-2014-7236 CRITICAL

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

Feb 17, 2020 7 affected product(s) NVD
9.1
CVSS
55.6%
EPSS
⚡ 53.1
CVE-2013-1360 CRITICAL

An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.

Feb 11, 2020 12 affected product(s) NVD
9.8
CVSS
23.2%
EPSS
⚡ 46.2
CVE-2014-5091 CRITICAL

A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.

Feb 7, 2020 1 affected product(s) NVD
9.8
CVSS
15.2%
EPSS
⚡ 43.7
CVE-2014-4170 CRITICAL

A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.

Feb 13, 2020 1 affected product(s) NVD
9.8
CVSS
14.5%
EPSS
⚡ 43.5
CVE-2013-6236 CRITICAL

IZON IP 2.0.2: hard-coded password vulnerability

Feb 12, 2020 1 affected product(s) NVD
9.8
CVSS
10.2%
EPSS
⚡ 42.3
CVE-2020-3760 CRITICAL

Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Feb 13, 2020 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2011-3642 CRITICAL

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

Feb 8, 2020 2 affected product(s) NVD
9.6
CVSS
8.8%
EPSS
⚡ 41
CVE-2020-3742 CRITICAL

Adobe Acrobat and Reader versions, 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
5.8%
EPSS
⚡ 40.9
CVE-2020-3752 CRITICAL

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2020-3740 CRITICAL

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Feb 13, 2020 1 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7
CVE-2020-3743 CRITICAL

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2020-3745 CRITICAL

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2020-3746 CRITICAL

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7