CSV
14,738 results for "vulnerability" Page 40
CVE-2017-1002000 CRITICAL

Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
27.4%
EPSS
⚡ 47.4
CVE-2017-1002008 CRITICAL

Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
16.9%
EPSS
⚡ 44.3
CVE-2017-14244 CRITICAL

An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

Sep 17, 2017 1 affected product(s) NVD
9.8
CVSS
17.1%
EPSS
⚡ 44.3
CVE-2017-13067 CRITICAL

QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.

Sep 14, 2017 2 affected product(s) NVD
9.8
CVSS
16.7%
EPSS
⚡ 44.2
CVE-2017-14243 CRITICAL

An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.

Sep 17, 2017 1 affected product(s) NVD
9.8
CVSS
14.8%
EPSS
⚡ 43.6
CVE-2017-1002002 CRITICAL

Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
12.6%
EPSS
⚡ 43
CVE-2017-1002003 CRITICAL

Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
12.3%
EPSS
⚡ 42.9
CVE-2017-1002001 CRITICAL

Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
11.1%
EPSS
⚡ 42.5
CVE-2017-9328 CRITICAL

Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.

Sep 15, 2017 1 affected product(s) NVD
9.8
CVSS
7.4%
EPSS
⚡ 41.4
CVE-2017-11462 CRITICAL

Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.

Sep 13, 2017 15 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2017-12905 CRITICAL

Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.

Sep 25, 2017 2 affected product(s) NVD
10.0
CVSS
2.6%
EPSS
⚡ 40.8
CVE-2017-1002020 CRITICAL

Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-1002021 CRITICAL

Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-1002022 CRITICAL

Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-1002012 CRITICAL

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2017-14624 CRITICAL

ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders/ps.c.

Sep 21, 2017 5 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-14625 CRITICAL

ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c.

Sep 21, 2017 5 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-14648 CRITICAL

A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

Sep 21, 2017 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2017-1002013 CRITICAL

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2017-1002014 CRITICAL

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.

Sep 14, 2017 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1