CSV
14,738 results for "vulnerability" Page 39
CVE-2017-8686 CRITICAL

The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".

Sep 13, 2017 3 affected product(s) NVD
9.8
CVSS
27.5%
EPSS
⚡ 47.4
CVE-2017-1002000 CRITICAL

Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
27.4%
EPSS
⚡ 47.4
CVE-2015-8351 CRITICAL

PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.

Sep 11, 2017 1 affected product(s) NVD
9.0
CVSS
37.0%
EPSS
⚡ 47.1
CVE-2017-1002008 CRITICAL

Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
16.9%
EPSS
⚡ 44.3
CVE-2017-1002002 CRITICAL

Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
12.6%
EPSS
⚡ 43
CVE-2015-7241 CRITICAL

XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.

Sep 6, 2017 1 affected product(s) NVD
9.8
CVSS
12.4%
EPSS
⚡ 42.9
CVE-2017-1002003 CRITICAL

Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
12.3%
EPSS
⚡ 42.9
CVE-2017-3897 CRITICAL

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

Sep 1, 2017 2 affected product(s) NVD
9.8
CVSS
11.7%
EPSS
⚡ 42.7
CVE-2017-1002001 CRITICAL

Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
11.1%
EPSS
⚡ 42.5
CVE-2015-3313 CRITICAL

SQL injection vulnerability in WordPress Community Events plugin before 1.4.

Sep 7, 2017 1 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2017-11462 CRITICAL

Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.

Sep 13, 2017 15 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2017-9834 CRITICAL

SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.

Sep 7, 2017 1 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2017-1002020 CRITICAL

Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-1002021 CRITICAL

Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-1002012 CRITICAL

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2015-1401 CRITICAL

Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.

Aug 28, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-1002013 CRITICAL

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-1002014 CRITICAL

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-1002015 CRITICAL

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-1002016 CRITICAL

Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
2.6%
EPSS
⚡ 40