CSV
14,854 results for "vulnerability" Page 95
CVE-2018-1160 CRITICAL Exploit

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

Dec 20, 2018 8 affected product(s) NVD
9.8
CVSS
86.5%
EPSS
⚡ 75.2
CVE-2018-7836 CRITICAL

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

Dec 24, 2018 1 affected product(s) NVD
9.8
CVSS
32.0%
EPSS
⚡ 48.8
CVE-2018-1000832 CRITICAL

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
6.4%
EPSS
⚡ 41.1
CVE-2018-1000838 CRITICAL

autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted CaseMetadata.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
2.5%
EPSS
⚡ 40.8
CVE-2018-1000820 CRITICAL

neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000821 CRITICAL

MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted SMathStudio files. This vulnerability appears to have been fixed in after commit 5c05ac8.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000822 CRITICAL

codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via specially crafted GSA XML files. This vulnerability appears to have been fixed in after commit faa265b.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000823 CRITICAL

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.

Dec 20, 2018 5 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000825 CRITICAL

FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Freecol file.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000831 CRITICAL

K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious WebDAV server or intercept the reponse of a valid WebDAV server.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000835 CRITICAL

KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.

Dec 20, 2018 17 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.5
CVE-2018-1000837 CRITICAL

UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious plugins.xml file.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.5
CVE-2018-1000830 CRITICAL

XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.

Dec 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.4
CVE-2018-7800 CRITICAL

A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device.

Dec 24, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-1000827 CRITICAL

Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2018-1000881 CRITICAL

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2018-15723 CRITICAL

The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2018-1000824 CRITICAL

MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-1000833 CRITICAL

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-1000885 CRITICAL

PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec() phkp.php:98 that can result in It is possible to manipulate gpg-keys or execute commands remotely. This attack appear to be exploitable via HKP-Api: /pks/lookup?search.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2