CSV
14,882 results for "vulnerability" Page 91
CVE-2018-9206 CRITICAL Exploit

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

Oct 11, 2018 1 affected product(s) NVD
9.8
CVSS
97.3%
EPSS
⚡ 78.4
CVE-2018-3245 CRITICAL Exploit

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
9.8
CVSS
94.3%
EPSS
⚡ 77.5
CVE-2018-10933 CRITICAL Exploit

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Oct 17, 2018 15 affected product(s) NVD
9.1
CVSS
91.8%
EPSS
⚡ 73.9
CVE-2018-14558 CRITICAL KEV Exploit

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.

Oct 30, 2018 3 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 71.8
CVE-2018-3191 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
9.8
CVSS
63.2%
EPSS
⚡ 58.2
CVE-2018-3252 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
9.8
CVSS
28.0%
EPSS
⚡ 47.6
CVE-2018-7076 CRITICAL

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04.

Oct 17, 2018 10 affected product(s) NVD
9.8
CVSS
12.3%
EPSS
⚡ 42.9
CVE-2018-12813 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
11.2%
EPSS
⚡ 42.6
CVE-2018-12814 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
11.2%
EPSS
⚡ 42.6
CVE-2018-4013 CRITICAL

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

Oct 19, 2018 3 affected product(s) NVD
9.8
CVSS
9.7%
EPSS
⚡ 42.1
CVE-2018-16462 CRITICAL

A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.

Oct 30, 2018 1 affected product(s) NVD
10.0
CVSS
7.0%
EPSS
⚡ 42.1
CVE-2018-12823 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2018-12822 CRITICAL

Adobe Digital Editions versions 4.5.8 and below have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
8.0%
EPSS
⚡ 41.6
CVE-2018-2913 CRITICAL

Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Monitoring Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle GoldenGate. While the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. Note: For Linux and Windows platforms, the CVSS score is 9.0 with Access Complexity as High. For all other platforms, the cvss score is 10.0. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Oct 17, 2018 3 affected product(s) NVD
10.0
CVSS
4.2%
EPSS
⚡ 41.3
CVE-2018-17893 CRITICAL

LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2018-14806 CRITICAL

Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code.

Oct 23, 2018 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2018-5188 CRITICAL

Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Oct 18, 2018 20 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-16461 CRITICAL

A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.

Oct 30, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-5156 CRITICAL

A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Oct 18, 2018 20 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2018-3197 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oct 17, 2018 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2