CSV
14,855 results for "vulnerability" Page 98
CVE-2018-20753 CRITICAL KEV Exploit

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

Feb 5, 2019 3 affected product(s) NVD
9.8
CVSS
29.3%
EPSS
⚡ 78
CVE-2018-3991 CRITICAL

An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can send a malformed TCP packet to trigger this vulnerability.

Feb 5, 2019 4 affected product(s) NVD
10.0
CVSS
34.3%
EPSS
⚡ 50.3
CVE-2019-6339 CRITICAL

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

Jan 22, 2019 5 affected product(s) NVD
9.8
CVSS
33.2%
EPSS
⚡ 49.2
CVE-2018-18500 CRITICAL

A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Feb 5, 2019 18 affected product(s) NVD
9.8
CVSS
12.7%
EPSS
⚡ 43
CVE-2019-7297 CRITICAL

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.

Jan 31, 2019 1 affected product(s) NVD
9.8
CVSS
12.5%
EPSS
⚡ 42.9
CVE-2018-19716 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
9.7%
EPSS
⚡ 42.1
CVE-2018-18505 CRITICAL

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Feb 5, 2019 18 affected product(s) NVD
10.0
CVSS
4.5%
EPSS
⚡ 41.4
CVE-2018-19698 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2018-19700 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2018-16039 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-16040 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-19702 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.6%
EPSS
⚡ 40.9
CVE-2018-19707 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-19708 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-19715 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2019-7731 CRITICAL

MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file.

Feb 11, 2019 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2018-6444 CRITICAL

A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands.

Jan 22, 2019 2 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2019-6798 CRITICAL

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.

Jan 26, 2019 1 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.2
CVE-2018-20749 CRITICAL

LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Jan 30, 2019 14 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-20750 CRITICAL

LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Jan 30, 2019 14 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2