CSV
14,738 results for "vulnerability" Page 38
CVE-2017-8686 CRITICAL

The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".

Sep 13, 2017 3 affected product(s) NVD
9.8
CVSS
27.5%
EPSS
⚡ 47.4
CVE-2015-8351 CRITICAL

PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.

Sep 11, 2017 1 affected product(s) NVD
9.0
CVSS
37.0%
EPSS
⚡ 47.1
CVE-2017-12965 CRITICAL

Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

Aug 23, 2017 1 affected product(s) NVD
9.8
CVSS
15.7%
EPSS
⚡ 43.9
CVE-2015-8352 CRITICAL

Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.

Aug 24, 2017 1 affected product(s) NVD
9.8
CVSS
15.6%
EPSS
⚡ 43.9
CVE-2015-7241 CRITICAL

XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.

Sep 6, 2017 1 affected product(s) NVD
9.8
CVSS
12.4%
EPSS
⚡ 42.9
CVE-2017-3897 CRITICAL

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

Sep 1, 2017 2 affected product(s) NVD
9.8
CVSS
11.7%
EPSS
⚡ 42.7
CVE-2015-3313 CRITICAL

SQL injection vulnerability in WordPress Community Events plugin before 1.4.

Sep 7, 2017 1 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2017-12791 CRITICAL

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

Aug 23, 2017 2 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2017-9834 CRITICAL

SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.

Sep 7, 2017 1 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2017-12858 CRITICAL

Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.

Aug 23, 2017 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2015-1401 CRITICAL

Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.

Aug 28, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-7420 CRITICAL

An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the running product (CWE-275).

Aug 21, 2017 7 affected product(s) NVD
9.8
CVSS
2.4%
EPSS
⚡ 39.9
CVE-2014-8428 CRITICAL

Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

Aug 28, 2017 1 affected product(s) NVD
9.8
CVSS
2.4%
EPSS
⚡ 39.9
CVE-2015-7700 CRITICAL

Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.

Aug 31, 2017 1 affected product(s) NVD
9.8
CVSS
2.2%
EPSS
⚡ 39.9
CVE-2017-9458 CRITICAL

XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via unspecified vectors.

Sep 7, 2017 29 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 39.9
CVE-2013-7426 CRITICAL

Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.

Aug 29, 2017 1 affected product(s) NVD
9.8
CVSS
2.2%
EPSS
⚡ 39.8
CVE-2017-14138 CRITICAL

ImageMagick 7.0.6-5 has a memory leak vulnerability in ReadWEBPImage in coders/webp.c because memory is not freed in certain error cases, as demonstrated by VP8 errors.

Sep 4, 2017 1 affected product(s) NVD
9.8
CVSS
2.1%
EPSS
⚡ 39.8
CVE-2016-10405 CRITICAL

Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.

Sep 7, 2017 1 affected product(s) NVD
9.8
CVSS
1.9%
EPSS
⚡ 39.8
CVE-2017-10842 CRITICAL

SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Aug 29, 2017 2 affected product(s) NVD
9.8
CVSS
1.8%
EPSS
⚡ 39.7
CVE-2017-14035 CRITICAL

CrushFTP 8.x before 8.2.0 has a serialization vulnerability.

Aug 30, 2017 4 affected product(s) NVD
9.8
CVSS
1.6%
EPSS
⚡ 39.7