CSV
14,883 results for "vulnerability" Page 94
CVE-2018-1000861 CRITICAL KEV Exploit

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

Dec 10, 2018 3 affected product(s) NVD
9.8
CVSS
98.3%
EPSS
⚡ 98.7
CVE-2018-8540 CRITICAL

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 4.6.2.

Dec 12, 2018 10 affected product(s) NVD
9.8
CVSS
22.1%
EPSS
⚡ 45.8
CVE-2018-8626 CRITICAL

A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.

Dec 12, 2018 9 affected product(s) NVD
9.8
CVSS
21.1%
EPSS
⚡ 45.5
CVE-2018-15127 CRITICAL

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

Dec 19, 2018 13 affected product(s) NVD
9.8
CVSS
15.1%
EPSS
⚡ 43.7
CVE-2018-15981 CRITICAL

Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Nov 29, 2018 7 affected product(s) NVD
9.8
CVSS
11.7%
EPSS
⚡ 42.7
CVE-2018-15126 CRITICAL

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution

Dec 19, 2018 7 affected product(s) NVD
9.8
CVSS
11.8%
EPSS
⚡ 42.7
CVE-2018-7364 CRITICAL

All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to execute arbitrary code with root privileges.

Dec 7, 2018 1 affected product(s) NVD
9.8
CVSS
10.3%
EPSS
⚡ 42.3
CVE-2018-20020 CRITICAL

LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution

Dec 19, 2018 7 affected product(s) NVD
9.8
CVSS
8.6%
EPSS
⚡ 41.8
CVE-2018-17930 CRITICAL

A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code execution.

Nov 28, 2018 1 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2018-1000832 CRITICAL

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2018-13816 CRITICAL

A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although configured. Successful exploitation requires an attacker to be able to send packets to port 102/tcp of the affected device. No user interaction and no user privileges are required to exploit the vulnerability. At the time of advisory publication no public exploitation of this vulnerability was known.

Dec 12, 2018 1 affected product(s) NVD
10.0
CVSS
2.8%
EPSS
⚡ 40.8
CVE-2018-1000838 CRITICAL

autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted CaseMetadata.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
2.5%
EPSS
⚡ 40.8
CVE-2018-1000820 CRITICAL

neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000821 CRITICAL

MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted SMathStudio files. This vulnerability appears to have been fixed in after commit 5c05ac8.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000822 CRITICAL

codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via specially crafted GSA XML files. This vulnerability appears to have been fixed in after commit faa265b.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000823 CRITICAL

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.

Dec 20, 2018 5 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000825 CRITICAL

FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Freecol file.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000831 CRITICAL

K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious WebDAV server or intercept the reponse of a valid WebDAV server.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-18619 CRITICAL

internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued.

Nov 29, 2018 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2018-1000835 CRITICAL

KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.

Dec 20, 2018 17 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.5