CSV
14,736 results for "vulnerability" Page 80
CVE-2018-7602 CRITICAL KEV Exploit

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

Jul 19, 2018 6 affected product(s) NVD
9.8
CVSS
99.2%
EPSS
⚡ 99
CVE-2018-2893 CRITICAL Exploit

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jul 18, 2018 4 affected product(s) NVD
9.8
CVSS
71.2%
EPSS
⚡ 70.6
CVE-2018-2894 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Jul 18, 2018 4 affected product(s) NVD
9.8
CVSS
50.2%
EPSS
⚡ 54.3
CVE-2018-14009 CRITICAL

Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.

Jul 12, 2018 1 affected product(s) NVD
9.8
CVSS
38.4%
EPSS
⚡ 50.7
CVE-2018-12754 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
25.3%
EPSS
⚡ 46.8
CVE-2018-12755 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
25.3%
EPSS
⚡ 46.8
CVE-2016-9498 CRITICAL

ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of system administrator, by exploiting this vulnerability an attacker gains highest privileges on the underlying operating system.

Jul 13, 2018 2 affected product(s) NVD
9.8
CVSS
22.0%
EPSS
⚡ 45.8
CVE-2018-8327 CRITICAL

A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.

Jul 11, 2018 2 affected product(s) NVD
9.8
CVSS
21.2%
EPSS
⚡ 45.6
CVE-2018-12463 CRITICAL

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Jul 12, 2018 3 affected product(s) NVD
9.8
CVSS
13.8%
EPSS
⚡ 43.4
CVE-2018-12782 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
11.2%
EPSS
⚡ 42.6
CVE-2018-12785 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
10.9%
EPSS
⚡ 42.5
CVE-2018-12784 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Buffer Errors vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
9.6%
EPSS
⚡ 42.1
CVE-2018-4996 CRITICAL

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 9, 2018 6 affected product(s) NVD
9.8
CVSS
9.0%
EPSS
⚡ 41.9
CVE-2018-12756 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.8%
EPSS
⚡ 41.9
CVE-2018-12791 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2018-12758 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2018-12760 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2018-12787 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2018-8319 CRITICAL

A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability." This affects Microsoft Research JavaScript Cryptography Library.

Jul 11, 2018 1 affected product(s) NVD
9.8
CVSS
7.0%
EPSS
⚡ 41.3
CVE-2018-8847 CRITICAL

Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution.

Jul 13, 2018 1 affected product(s) NVD
9.8
CVSS
6.8%
EPSS
⚡ 41.3