CSV
14,737 results for "vulnerability" Page 33
CVE-2017-9828 CRITICAL Exploit

'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.

Jun 23, 2017 3 affected product(s) NVD
9.8
CVSS
82.5%
EPSS
⚡ 73.9
CVE-2017-1000002 CRITICAL

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.

Jul 17, 2017 1 affected product(s) NVD
9.8
CVSS
30.8%
EPSS
⚡ 48.4
CVE-2017-11389 CRITICAL

Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.

Aug 2, 2017 1 affected product(s) NVD
9.8
CVSS
27.4%
EPSS
⚡ 47.4
CVE-2017-8589 CRITICAL

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

Jul 11, 2017 12 affected product(s) NVD
9.8
CVSS
26.2%
EPSS
⚡ 47
CVE-2017-0028 CRITICAL

A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."

Jul 17, 2017 1 affected product(s) NVD
9.8
CVSS
18.9%
EPSS
⚡ 44.9
CVE-2017-11444 CRITICAL

Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.

Jul 19, 2017 1 affected product(s) NVD
9.8
CVSS
13.1%
EPSS
⚡ 43.1
CVE-2017-11435 CRITICAL

The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.

Jul 19, 2017 1 affected product(s) NVD
9.8
CVSS
10.1%
EPSS
⚡ 42.2
CVE-2017-9629 CRITICAL

A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow a remote attacker to execute arbitrary code in the context of a highly privileged account.

Jul 7, 2017 1 affected product(s) NVD
9.8
CVSS
9.8%
EPSS
⚡ 42.1
CVE-2017-10682 CRITICAL

SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.

Jun 29, 2017 1 affected product(s) NVD
9.8
CVSS
8.2%
EPSS
⚡ 41.7
CVE-2016-0959 CRITICAL

Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet Explorer 10 and 11 before 20.0.0.267, Adobe Flash Player for Linux before 11.2.202.559, AIR Desktop Runtime before 20.0.0.233, AIR SDK before 20.0.0.233, AIR SDK & Compiler before 20.0.0.233, AIR for Android before 20.0.0.233.

Jun 27, 2017 11 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2017-4997 CRITICAL

EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.

Jun 29, 2017 1 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.5
CVE-2017-10685 CRITICAL

In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.

Jun 29, 2017 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2017-6714 CRITICAL

A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An attacker could exploit this vulnerability by crafting CLI command inputs to execute Linux shell commands as the root user. This vulnerability affects all releases of Cisco Ultra Services Framework Staging Server prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76673.

Jul 6, 2017 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2017-1253 CRITICAL

IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 124633.

Jul 5, 2017 4 affected product(s) NVD
9.9
CVSS
2.3%
EPSS
⚡ 40.3
CVE-2017-11494 CRITICAL

SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.

Aug 2, 2017 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2017-4053 CRITICAL

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.

Jul 12, 2017 4 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2015-2798 CRITICAL

SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Jul 25, 2017 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2017-6713 CRITICAL

A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vulnerability is due to static, default credentials for the Cisco ESC UI that are shared between installations. An attacker who can extract the static credentials from an existing installation of Cisco ESC could generate an admin session token that allows access to all instances of the ESC web UI. This vulnerability affects Cisco Elastic Services Controller prior to releases 2.3.1.434 and 2.3.2. Cisco Bug IDs: CSCvc76627.

Jul 6, 2017 6 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-11381 CRITICAL

A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.

Aug 1, 2017 1 affected product(s) NVD
9.8
CVSS
3.1%
EPSS
⚡ 40.1
CVE-2015-1174 CRITICAL

Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.

Aug 2, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1