CSV
14,735 results for "vulnerability" Page 34
CVE-2017-11394 CRITICAL

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.

Aug 3, 2017 2 affected product(s) NVD
9.8
CVSS
66.8%
EPSS
⚡ 59.2
CVE-2017-1000002 CRITICAL

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.

Jul 17, 2017 1 affected product(s) NVD
9.8
CVSS
30.8%
EPSS
⚡ 48.4
CVE-2017-11389 CRITICAL

Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.

Aug 2, 2017 1 affected product(s) NVD
9.8
CVSS
27.4%
EPSS
⚡ 47.4
CVE-2017-0028 CRITICAL

A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."

Jul 17, 2017 1 affected product(s) NVD
9.8
CVSS
18.9%
EPSS
⚡ 44.9
CVE-2017-11151 CRITICAL

A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.

Aug 8, 2017 2 affected product(s) NVD
9.8
CVSS
16.3%
EPSS
⚡ 44.1
CVE-2017-11393 CRITICAL

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.

Aug 3, 2017 2 affected product(s) NVD
9.8
CVSS
15.9%
EPSS
⚡ 44
CVE-2017-11444 CRITICAL

Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.

Jul 19, 2017 1 affected product(s) NVD
9.8
CVSS
13.1%
EPSS
⚡ 43.1
CVE-2017-11435 CRITICAL

The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.

Jul 19, 2017 1 affected product(s) NVD
9.8
CVSS
10.1%
EPSS
⚡ 42.2
CVE-2017-10137 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JNDI). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Aug 8, 2017 2 affected product(s) NVD
10.0
CVSS
3.8%
EPSS
⚡ 41.1
CVE-2017-6747 CRITICAL

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users. An attacker could exploit this vulnerability by authenticating with a valid external user account that matches an internal username and incorrectly receiving the authorization policy of the internal account. An exploit could allow the attacker to have Super Admin privileges for the ISE Admin portal. This vulnerability does not affect endpoints authenticating to the ISE. The vulnerability affects Cisco ISE, Cisco ISE Express, and Cisco ISE Virtual Appliance running Release 1.3, 1.4, 2.0.0, 2.0.1, or 2.1.0. Release 2.2.x is not affected. Cisco Bug IDs: CSCvb10995.

Aug 7, 2017 18 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2017-11494 CRITICAL

SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.

Aug 2, 2017 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2017-10202 CRITICAL

Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While the vulnerability is in OJVM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of OJVM. Note: This score is for Windows platforms. On non-Windows platforms Scope is Unchanged, giving a CVSS Base Score of 8.8. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Aug 8, 2017 3 affected product(s) NVD
9.9
CVSS
2.3%
EPSS
⚡ 40.3
CVE-2017-4053 CRITICAL

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.

Jul 12, 2017 4 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2015-2798 CRITICAL

SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Jul 25, 2017 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2017-11381 CRITICAL

A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.

Aug 1, 2017 1 affected product(s) NVD
9.8
CVSS
3.1%
EPSS
⚡ 40.1
CVE-2015-1174 CRITICAL

Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.

Aug 2, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-6869 CRITICAL

A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.

Aug 8, 2017 1 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2017-1000003 CRITICAL

ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Module component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to a incorrect access control check vulnerability in the Alternative Content component resulting in privilege escalation.

Jul 17, 2017 1 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9
CVE-2017-11720 CRITICAL

There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.

Jul 28, 2017 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 39.9
CVE-2017-10816 CRITICAL

SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server.

Aug 4, 2017 2 affected product(s) NVD
9.8
CVSS
2.2%
EPSS
⚡ 39.9