CSV
14,738 results for "vulnerability" Page 83
CVE-2018-14847 CRITICAL KEV Exploit

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Aug 2, 2018 1 affected product(s) NVD
9.1
CVSS
96.1%
EPSS
⚡ 95.2
CVE-2018-14417 CRITICAL Exploit

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

Aug 4, 2018 1 affected product(s) NVD
9.8
CVSS
89.6%
EPSS
⚡ 76.1
CVE-2016-5649 CRITICAL

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.

Jul 24, 2018 2 affected product(s) NVD
9.8
CVSS
27.2%
EPSS
⚡ 47.4
CVE-2018-13416 CRITICAL

In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running UMS, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Aug 3, 2018 1 affected product(s) NVD
9.8
CVSS
20.2%
EPSS
⚡ 45.3
CVE-2016-4391 CRITICAL

A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
20.4%
EPSS
⚡ 45.3
CVE-2017-8990 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506). This issue was resolved in HPE IMC Wireless Services Manager Software IMC WSM 7.3 E0506P01 or subsequent version.

Aug 6, 2018 2 affected product(s) NVD
9.8
CVSS
16.7%
EPSS
⚡ 44.2
CVE-2018-7074 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. The vulnerability was resolved in iMC PLAT 7.3 E0605P04 or subsequent version.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
16.7%
EPSS
⚡ 44.2
CVE-2016-4402 CRITICAL

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via buffer overflow.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
16.4%
EPSS
⚡ 44.1
CVE-2016-4404 CRITICAL

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via a memory allocation issue.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
14.8%
EPSS
⚡ 43.6
CVE-2016-4403 CRITICAL

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via memory corruption.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
13.6%
EPSS
⚡ 43.3
CVE-2018-5924 CRITICAL

A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.

Aug 13, 2018 270 affected product(s) NVD
9.8
CVSS
12.2%
EPSS
⚡ 42.9
CVE-2018-3779 CRITICAL

active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.

Aug 10, 2018 1 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2018-9866 CRITICAL

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

Aug 3, 2018 1 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.6
CVE-2018-7058 CRITICAL

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-15168 CRITICAL

A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.

Aug 8, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-3110 CRITICAL

A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Aug 10, 2018 4 affected product(s) NVD
9.9
CVSS
2.5%
EPSS
⚡ 40.3
CVE-2018-7072 CRITICAL

A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
3.1%
EPSS
⚡ 40.1
CVE-2017-14444 CRITICAL

An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly handles the URL parameter during a firmware update request, leading to a buffer overflow on a global section. An attacker can send an HTTP GET request to trigger this vulnerability.

Aug 2, 2018 1 affected product(s) NVD
9.9
CVSS
1.4%
EPSS
⚡ 40
CVE-2017-14446 CRITICAL

An exploitable stack-based buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation unsafely extracts parameters from the query string, leading to a buffer overflow on the stack. An attacker can send an HTTP GET request to trigger this vulnerability.

Aug 2, 2018 1 affected product(s) NVD
9.9
CVSS
1.3%
EPSS
⚡ 40
CVE-2017-16338 CRITICAL

An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bad0 the value for the host key is copied using strcpy to the buffer at 0xa00016e0. This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

Aug 2, 2018 1 affected product(s) NVD
9.9
CVSS
1.4%
EPSS
⚡ 40