CSV
14,738 results for "vulnerability" Page 84
CVE-2018-14417 CRITICAL Exploit

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

Aug 4, 2018 1 affected product(s) NVD
9.8
CVSS
89.6%
EPSS
⚡ 76.1
CVE-2018-13415 CRITICAL

In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Plex, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Aug 13, 2018 1 affected product(s) NVD
9.8
CVSS
31.8%
EPSS
⚡ 48.7
CVE-2018-8273 CRITICAL

A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

Aug 15, 2018 3 affected product(s) NVD
9.8
CVSS
29.2%
EPSS
⚡ 48
CVE-2018-8302 CRITICAL

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

Aug 15, 2018 5 affected product(s) NVD
9.8
CVSS
25.5%
EPSS
⚡ 46.9
CVE-2018-13417 CRITICAL

In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Vuze, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Aug 13, 2018 1 affected product(s) NVD
9.8
CVSS
20.7%
EPSS
⚡ 45.4
CVE-2018-13416 CRITICAL

In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running UMS, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Aug 3, 2018 1 affected product(s) NVD
9.8
CVSS
20.2%
EPSS
⚡ 45.3
CVE-2016-4391 CRITICAL

A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
20.4%
EPSS
⚡ 45.3
CVE-2017-8990 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506). This issue was resolved in HPE IMC Wireless Services Manager Software IMC WSM 7.3 E0506P01 or subsequent version.

Aug 6, 2018 2 affected product(s) NVD
9.8
CVSS
16.7%
EPSS
⚡ 44.2
CVE-2018-7074 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. The vulnerability was resolved in iMC PLAT 7.3 E0605P04 or subsequent version.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
16.7%
EPSS
⚡ 44.2
CVE-2018-15152 CRITICAL

Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.

Aug 15, 2018 1 affected product(s) NVD
9.1
CVSS
25.9%
EPSS
⚡ 44.2
CVE-2016-4402 CRITICAL

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via buffer overflow.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
16.4%
EPSS
⚡ 44.1
CVE-2016-4404 CRITICAL

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via a memory allocation issue.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
14.8%
EPSS
⚡ 43.6
CVE-2016-4403 CRITICAL

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via memory corruption.

Aug 6, 2018 1 affected product(s) NVD
9.8
CVSS
13.6%
EPSS
⚡ 43.3
CVE-2018-5924 CRITICAL

A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.

Aug 13, 2018 270 affected product(s) NVD
9.8
CVSS
12.2%
EPSS
⚡ 42.9
CVE-2018-11511 CRITICAL

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.

Aug 16, 2018 1 affected product(s) NVD
9.8
CVSS
11.2%
EPSS
⚡ 42.6
CVE-2018-10510 CRITICAL

A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.

Aug 15, 2018 2 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.1
CVE-2018-3779 CRITICAL

active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.

Aug 10, 2018 1 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2018-10511 CRITICAL

A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.

Aug 15, 2018 2 affected product(s) NVD
10.0
CVSS
2.7%
EPSS
⚡ 40.8
CVE-2018-9866 CRITICAL

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

Aug 3, 2018 1 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.6
CVE-2018-1000644 CRITICAL

Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.

Aug 20, 2018 4 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6