CSV
14,855 results for "vulnerability" Page 99
CVE-2019-9194 CRITICAL Exploit

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

Feb 26, 2019 1 affected product(s) NVD
9.8
CVSS
96.7%
EPSS
⚡ 78.2
CVE-2018-20753 CRITICAL KEV Exploit

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

Feb 5, 2019 3 affected product(s) NVD
9.8
CVSS
29.3%
EPSS
⚡ 78
CVE-2019-8341 CRITICAL

An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing

Feb 15, 2019 3 affected product(s) NVD
9.8
CVSS
44.8%
EPSS
⚡ 52.6
CVE-2018-3991 CRITICAL

An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can send a malformed TCP packet to trigger this vulnerability.

Feb 5, 2019 4 affected product(s) NVD
10.0
CVSS
34.3%
EPSS
⚡ 50.3
CVE-2019-8917 CRITICAL

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.

Feb 18, 2019 1 affected product(s) NVD
9.8
CVSS
36.4%
EPSS
⚡ 50.1
CVE-2019-8985 CRITICAL

On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.

Feb 21, 2019 2 affected product(s) NVD
9.8
CVSS
13.3%
EPSS
⚡ 43.2
CVE-2018-18500 CRITICAL

A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Feb 5, 2019 18 affected product(s) NVD
9.8
CVSS
12.7%
EPSS
⚡ 43
CVE-2019-9021 CRITICAL

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.

Feb 22, 2019 10 affected product(s) NVD
9.8
CVSS
10.1%
EPSS
⚡ 42.2
CVE-2019-9184 CRITICAL

SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

Feb 26, 2019 1 affected product(s) NVD
9.8
CVSS
9.0%
EPSS
⚡ 41.9
CVE-2018-18505 CRITICAL

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Feb 5, 2019 18 affected product(s) NVD
10.0
CVSS
4.5%
EPSS
⚡ 41.4
CVE-2019-8395 CRITICAL

An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.

Feb 17, 2019 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2018-20122 CRITICAL

The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges. No authentication is required in order to trigger the vulnerability.

Feb 21, 2019 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2019-7731 CRITICAL

MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file.

Feb 11, 2019 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2018-20033 CRITICAL

A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.

Feb 25, 2019 2 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2019-9227 CRITICAL

An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter with malicious code can be written into the opt_base.inc.php file.

Feb 28, 2019 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2018-18501 CRITICAL

Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Feb 5, 2019 17 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.2
CVE-2018-12390 CRITICAL

Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

Feb 28, 2019 19 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-12392 CRITICAL

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

Feb 28, 2019 19 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2018-16492 CRITICAL

A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.

Feb 1, 2019 2 affected product(s) NVD
9.8
CVSS
3.1%
EPSS
⚡ 40.1
CVE-2018-4056 CRITICAL

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

Feb 5, 2019 3 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1