CSV
14,784 results for "vulnerability" Page 144
CVE-2020-9054 CRITICAL KEV Exploit

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2

Mar 4, 2020 27 affected product(s) NVD
9.8
CVSS
100.0%
EPSS
⚡ 99.2
CVE-2020-1938 CRITICAL KEV Exploit

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.

Feb 24, 2020 38 affected product(s) NVD
9.8
CVSS
99.3%
EPSS
⚡ 99
CVE-2020-8794 CRITICAL Exploit

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

Feb 25, 2020 7 affected product(s) NVD
9.8
CVSS
88.9%
EPSS
⚡ 75.9
CVE-2020-4211 CRITICAL Exploit

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
71.1%
EPSS
⚡ 70.5
CVE-2020-9374 CRITICAL

On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.

Feb 24, 2020 1 affected product(s) NVD
9.8
CVSS
42.7%
EPSS
⚡ 52
CVE-2020-4210 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.5%
EPSS
⚡ 43.8
CVE-2020-4213 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.5%
EPSS
⚡ 43.8
CVE-2020-4222 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.5%
EPSS
⚡ 43.8
CVE-2020-4212 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.0%
EPSS
⚡ 43.7
CVE-2020-8540 CRITICAL

An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Mar 11, 2020 1 affected product(s) NVD
9.8
CVSS
12.8%
EPSS
⚡ 43
CVE-2020-0690 CRITICAL

An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.

Mar 12, 2020 12 affected product(s) NVD
9.8
CVSS
7.0%
EPSS
⚡ 41.3
CVE-2019-5138 CRITICAL

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020 1 affected product(s) NVD
9.9
CVSS
5.2%
EPSS
⚡ 41.1
CVE-2020-3765 CRITICAL

Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

Feb 20, 2020 1 affected product(s) NVD
9.8
CVSS
5.9%
EPSS
⚡ 41
CVE-2014-4678 CRITICAL

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.

Feb 20, 2020 4 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2020-10224 CRITICAL

An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

Mar 8, 2020 1 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2020-6061 CRITICAL

An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.

Feb 19, 2020 10 affected product(s) NVD
9.8
CVSS
5.1%
EPSS
⚡ 40.7
CVE-2014-9612 CRITICAL

SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.

Feb 19, 2020 3 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2020-10225 CRITICAL

An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

Mar 8, 2020 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2019-15609 CRITICAL

The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.

Feb 28, 2020 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2020-10108 CRITICAL

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

Mar 12, 2020 11 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4