CSV
14,854 results for "vulnerability" Page 96
CVE-2018-1160 CRITICAL Exploit

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

Dec 20, 2018 8 affected product(s) NVD
9.8
CVSS
86.5%
EPSS
⚡ 75.2
CVE-2019-0547 CRITICAL Exploit

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.

Jan 8, 2019 1 affected product(s) NVD
9.8
CVSS
71.4%
EPSS
⚡ 70.6
CVE-2018-7836 CRITICAL

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

Dec 24, 2018 1 affected product(s) NVD
9.8
CVSS
32.0%
EPSS
⚡ 48.8
CVE-2019-0586 CRITICAL

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

Jan 8, 2019 3 affected product(s) NVD
9.8
CVSS
15.4%
EPSS
⚡ 43.8
CVE-2018-16036 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-16037 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2019-0006 CRITICAL

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. This issue only occurs when the crafted packet it destined to the device. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D47 on EX and QFX Virtual Chassis Platforms; 15.1 versions prior to 15.1R7-S3 all Virtual Chassis Platforms 15.1X53 versions prior to 15.1X53-D50 on EX and QFX Virtual Chassis Platforms.

Jan 15, 2019 26 affected product(s) NVD
9.8
CVSS
5.3%
EPSS
⚡ 40.8
CVE-2018-7800 CRITICAL

A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device.

Dec 24, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-1000881 CRITICAL

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2018-15723 CRITICAL

The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2018-1000885 CRITICAL

PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec() phkp.php:98 that can result in It is possible to manipulate gpg-keys or execute commands remotely. This attack appear to be exploitable via HKP-Api: /pks/lookup?search.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-20325 CRITICAL

There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.

Dec 21, 2018 1 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.2
CVE-2018-13045 CRITICAL

SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.

Jan 2, 2019 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-1000854 CRITICAL

esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT that can result in Remote Code Execution. This attack appear to be exploitable via Use of another weakness in backend application to reflect ESI directives. This vulnerability appears to have been fixed in 5.3.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.1
CVE-2018-1000626 CRITICAL

Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement to change the default API key. An attacker could exploit this vulnerability using all available API functions containing an unchanged API key to gain unauthorized access to the system.

Dec 28, 2018 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40.1
CVE-2018-1000628 CRITICAL

Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the direct checking of the API key against a user-supplied value in PHP's GET global variable array using PHP's strcmp() function. By adding "[]" to the end of "key" in the URL when accessing API functions, an attacker could exploit this vulnerability to execute API functions.

Dec 28, 2018 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40.1
CVE-2017-6925 CRITICAL

In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs, and entities that have different access restrictions on different revisions of the same entity.

Jan 15, 2019 1 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2018-18399 CRITICAL

SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.

Dec 20, 2018 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40
CVE-2018-1000625 CRITICAL

Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and gain unauthorized access to the system.

Dec 28, 2018 1 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9
CVE-2018-1000627 CRITICAL

Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to the API key file. An attacker could exploit this vulnerability to obtain the current API key to gain unauthorized access to the system.

Dec 28, 2018 1 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9