CSV
14,882 results for "vulnerability" Page 88
CVE-2018-15961 CRITICAL KEV Exploit

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
100.0%
EPSS
⚡ 99.2
CVE-2018-17153 CRITICAL Exploit

It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called "cgi_get_ipv6" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter "flag" with the value "1" is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie.

Sep 18, 2018 12 affected product(s) NVD
9.8
CVSS
86.6%
EPSS
⚡ 75.2
CVE-2015-9266 CRITICAL Exploit

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

Sep 5, 2018 12 affected product(s) NVD
9.8
CVSS
74.0%
EPSS
⚡ 71.4
CVE-2018-16836 CRITICAL

Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.

Sep 11, 2018 1 affected product(s) NVD
9.8
CVSS
61.4%
EPSS
⚡ 57.6
CVE-2018-12848 CRITICAL

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 6 affected product(s) NVD
9.8
CVSS
34.7%
EPSS
⚡ 49.6
CVE-2018-8421 CRITICAL

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.

Sep 13, 2018 23 affected product(s) NVD
9.8
CVSS
28.9%
EPSS
⚡ 47.9
CVE-2018-15957 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
28.2%
EPSS
⚡ 47.7
CVE-2018-15958 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
25.9%
EPSS
⚡ 47
CVE-2018-15959 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
25.9%
EPSS
⚡ 47
CVE-2018-15965 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
25.9%
EPSS
⚡ 47
CVE-2018-1000802 CRITICAL

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

Sep 18, 2018 11 affected product(s) NVD
9.8
CVSS
20.8%
EPSS
⚡ 45.4
CVE-2018-14829 CRITICAL

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.

Sep 20, 2018 1 affected product(s) NVD
9.8
CVSS
16.1%
EPSS
⚡ 44
CVE-2018-7103 CRITICAL

A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

Sep 27, 2018 3 affected product(s) NVD
9.8
CVSS
8.9%
EPSS
⚡ 41.9
CVE-2018-7104 CRITICAL

A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

Sep 27, 2018 3 affected product(s) NVD
9.8
CVSS
8.9%
EPSS
⚡ 41.9
CVE-2018-1000666 CRITICAL

GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in method: notifySpaceModification; that can result in Improper validation of parameters results in command execution. This attack appear to be exploitable via Network connectivity, required minimal auth privileges (everyone can register an account). This vulnerability appears to have been fixed in After commit 15443122ed2b1cbfd7bdefc048bf106f075becdb.

Sep 6, 2018 2 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2018-15764 CRITICAL

Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code in the server's JVM.

Sep 28, 2018 1 affected product(s) NVD
9.8
CVSS
5.3%
EPSS
⚡ 40.8
CVE-2018-6320 CRITICAL

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.

Sep 6, 2018 18 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2018-11058 CRITICAL

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.

Sep 14, 2018 25 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2018-14813 CRITICAL

Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.

Sep 26, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-14823 CRITICAL

Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

Sep 26, 2018 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4