CSV
14,741 results for "vulnerability" Page 59
CVE-2018-6530 CRITICAL KEV Exploit

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

Mar 6, 2018 4 affected product(s) NVD
9.8
CVSS
96.7%
EPSS
⚡ 98.2
CVE-2018-0147 CRITICAL KEV Exploit

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

Mar 8, 2018 1 affected product(s) NVD
9.8
CVSS
18.3%
EPSS
⚡ 74.7
CVE-2018-8057 CRITICAL

A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.

Mar 11, 2018 1 affected product(s) NVD
9.8
CVSS
22.2%
EPSS
⚡ 45.9
CVE-2018-1216 CRITICAL

A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). They contain an undocumented default account (smc) with a hard-coded password that may be used with certain web servlets. A remote attacker with the knowledge of the hard-coded password and the message format may use vulnerable servlets to gain unauthorized access to the system. Note: This account cannot be used to log in via the web user interface.

Mar 8, 2018 4 affected product(s) NVD
9.8
CVSS
21.7%
EPSS
⚡ 45.7
CVE-2018-6481 CRITICAL

A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.

Feb 27, 2018 1 affected product(s) NVD
9.8
CVSS
20.7%
EPSS
⚡ 45.4
CVE-2018-5782 CRITICAL

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vsethost.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

Mar 14, 2018 2 affected product(s) NVD
9.8
CVSS
19.1%
EPSS
⚡ 44.9
CVE-2015-5377 CRITICAL

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

Mar 6, 2018 1 affected product(s) NVD
9.8
CVSS
14.3%
EPSS
⚡ 43.5
CVE-2018-4895 CRITICAL

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

Feb 27, 2018 6 affected product(s) NVD
9.8
CVSS
13.7%
EPSS
⚡ 43.3
CVE-2018-6223 CRITICAL

A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameters.

Mar 15, 2018 1 affected product(s) NVD
9.8
CVSS
10.2%
EPSS
⚡ 42.3
CVE-2018-6228 CRITICAL

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

Mar 15, 2018 1 affected product(s) NVD
9.8
CVSS
10.4%
EPSS
⚡ 42.3
CVE-2018-6229 CRITICAL

A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

Mar 15, 2018 1 affected product(s) NVD
9.8
CVSS
10.4%
EPSS
⚡ 42.3
CVE-2018-6220 CRITICAL

An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.

Mar 15, 2018 1 affected product(s) NVD
9.8
CVSS
10.0%
EPSS
⚡ 42.2
CVE-2018-1000116 CRITICAL

NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.

Mar 7, 2018 2 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2018-7538 CRITICAL

A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.

Mar 12, 2018 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2018-1000124 CRITICAL

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.

Mar 13, 2018 1 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.5
CVE-2017-18211 CRITICAL

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel.

Mar 1, 2018 30 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-5469 CRITICAL

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.

Mar 6, 2018 134 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40.1
CVE-2018-1000076 CRITICAL

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem could be installed, as the tarball would contain multiple gem signatures.. This vulnerability appears to have been fixed in 2.7.6.

Mar 13, 2018 5 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2018-7238 CRITICAL

A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to execute arbitrary code.

Mar 9, 2018 20 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40
CVE-2018-5779 CRITICAL

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests. Successful exploit could allow an attacker to execute arbitrary code within the context of the application.

Mar 14, 2018 2 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40