CSV
14,882 results for "vulnerability" Page 90
CVE-2018-9206 CRITICAL Exploit

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

Oct 11, 2018 1 affected product(s) NVD
9.8
CVSS
97.3%
EPSS
⚡ 78.4
CVE-2018-3245 CRITICAL Exploit

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
9.8
CVSS
94.3%
EPSS
⚡ 77.5
CVE-2018-15379 CRITICAL Exploit

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.

Oct 5, 2018 10 affected product(s) NVD
9.8
CVSS
86.2%
EPSS
⚡ 75.1
CVE-2018-10933 CRITICAL Exploit

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Oct 17, 2018 15 affected product(s) NVD
9.1
CVSS
91.8%
EPSS
⚡ 73.9
CVE-2018-3191 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
9.8
CVSS
63.2%
EPSS
⚡ 58.2
CVE-2018-3252 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
9.8
CVSS
28.0%
EPSS
⚡ 47.6
CVE-2018-8500 CRITICAL

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.

Oct 10, 2018 1 affected product(s) NVD
9.8
CVSS
18.5%
EPSS
⚡ 44.7
CVE-2018-7076 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04.

Oct 17, 2018 10 affected product(s) NVD
9.8
CVSS
12.3%
EPSS
⚡ 42.9
CVE-2018-12813 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
11.2%
EPSS
⚡ 42.6
CVE-2018-12814 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
11.2%
EPSS
⚡ 42.6
CVE-2018-12823 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2018-12822 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
8.0%
EPSS
⚡ 41.6
CVE-2018-2913 CRITICAL

Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Monitoring Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle GoldenGate. While the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. Note: For Linux and Windows platforms, the CVSS score is 9.0 with Access Complexity as High. For all other platforms, the cvss score is 10.0. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
10.0
CVSS
4.2%
EPSS
⚡ 41.3
CVE-2018-15427 CRITICAL

A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials. The vulnerability is due to the presence of undocumented, default, static user credentials for the root account of the affected software on certain systems. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.

Oct 5, 2018 3 affected product(s) NVD
9.8
CVSS
6.8%
EPSS
⚡ 41.2
CVE-2018-0426 CRITICAL

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to the targeted device. A successful exploit could allow the attacker to gain access to arbitrary files on the affected device, resulting in the disclosure of sensitive information.

Oct 5, 2018 3 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2018-1000804 CRITICAL

contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform Remote Code Execution on device using Contiki-NG operating system. This attack appear to be exploitable via Attacker must be able to run malicious AQL code (e.g. via SQL-like Injection attack).

Oct 8, 2018 1 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2018-17893 CRITICAL

LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2018-14790 CRITICAL

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.

Oct 1, 2018 1 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2015-9271 CRITICAL

The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905.

Oct 4, 2018 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2018-0425 CRITICAL

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to gain access to sensitive configuration information, including user authentication credentials.

Oct 5, 2018 3 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2