CSV
14,882 results for "vulnerability" Page 89
CVE-2018-15961 CRITICAL KEV Exploit

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
100.0%
EPSS
⚡ 99.2
CVE-2018-15379 CRITICAL Exploit

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.

Oct 5, 2018 10 affected product(s) NVD
9.8
CVSS
86.2%
EPSS
⚡ 75.1
CVE-2018-12848 CRITICAL

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 6 affected product(s) NVD
9.8
CVSS
34.7%
EPSS
⚡ 49.6
CVE-2018-15957 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
28.2%
EPSS
⚡ 47.7
CVE-2018-15958 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
25.9%
EPSS
⚡ 47
CVE-2018-15959 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
25.9%
EPSS
⚡ 47
CVE-2018-15965 CRITICAL

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Sep 25, 2018 23 affected product(s) NVD
9.8
CVSS
25.9%
EPSS
⚡ 47
CVE-2018-8500 CRITICAL

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.

Oct 10, 2018 1 affected product(s) NVD
9.8
CVSS
18.5%
EPSS
⚡ 44.7
CVE-2018-7103 CRITICAL

A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

Sep 27, 2018 3 affected product(s) NVD
9.8
CVSS
8.9%
EPSS
⚡ 41.9
CVE-2018-7104 CRITICAL

A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

Sep 27, 2018 3 affected product(s) NVD
9.8
CVSS
8.9%
EPSS
⚡ 41.9
CVE-2018-15427 CRITICAL

A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials. The vulnerability is due to the presence of undocumented, default, static user credentials for the root account of the affected software on certain systems. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.

Oct 5, 2018 3 affected product(s) NVD
9.8
CVSS
6.8%
EPSS
⚡ 41.2
CVE-2018-0426 CRITICAL

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to the targeted device. A successful exploit could allow the attacker to gain access to arbitrary files on the affected device, resulting in the disclosure of sensitive information.

Oct 5, 2018 3 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2018-1000804 CRITICAL

contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform Remote Code Execution on device using Contiki-NG operating system. This attack appear to be exploitable via Attacker must be able to run malicious AQL code (e.g. via SQL-like Injection attack).

Oct 8, 2018 1 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2018-15764 CRITICAL

Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code in the server's JVM.

Sep 28, 2018 1 affected product(s) NVD
9.8
CVSS
5.3%
EPSS
⚡ 40.8
CVE-2018-14790 CRITICAL

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.

Oct 1, 2018 1 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2015-9271 CRITICAL

The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905.

Oct 4, 2018 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2018-14813 CRITICAL

Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.

Sep 26, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-14823 CRITICAL

Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

Sep 26, 2018 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2018-3972 CRITICAL

An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially crafted network packet can cause a logic flaw, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

Sep 26, 2018 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2018-14817 CRITICAL

Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.

Sep 26, 2018 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3