94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2018-20062
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2018 2 PoCs

An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.

CVE-2018-18602
Software Genérico Web Cloud
9.8
CRITICAL
EPSS
0.3%
2018 1 PoC

The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

CVE-2018-7445
🔥 KEV Software Genérico Networking Windows
9.8
CRITICAL
EPSS
87.6%
2018 3 PoCs

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

CVE-2018-10561
🔥 KEV Software Genérico Networking
9.8
CRITICAL
EPSS
93.3%
2018 1 PoC

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

CVE-2018-11052
ECS Cloud
9.8
CRITICAL
EPSS
3.7%
2018 1 PoC

Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to read and modify S3 objects by supplying specially crafted S3 requests.

CVE-2018-14882
Software Genérico General
9.8
CRITICAL
EPSS
2.4%
2018 1 PoC

The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.

CVE-2018-11138
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2018 2 PoCs

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

CVE-2018-10682
Software Genérico General
9.8
CRITICAL
EPSS
7.4%
2018 1 PoC

An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default (auto-deployment) permits an anonymous user to deploy a malicious .war file, leading to remote code execution. NOTE: the vendor indicates that anonymous access is not available in the default installation; however, it remains optional because there are several use cases for it, including development environments and network archi

CVE-2018-25083
Software Genérico General
9.8
CRITICAL
EPSS
17.6%
2018 1 PoC

The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.

CVE-2018-15961
🔥 KEV ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2018 9 PoCs

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2018-6333
Nuclide General
9.8
CRITICAL
EPSS
1.1%
2018 CWE-79 1 PoC

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.

CVE-2018-14881
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2018 1 PoC

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

CVE-2018-1000861
🔥 KEV Software Genérico DevOps ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2018 2 PoCs

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

CVE-2018-10562
🔥 KEV Software Genérico Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2018 2 PoCs

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

CVE-2018-15764
ESRS Policy Manager General
9.8
CRITICAL
EPSS
9.1%
2018 1 PoC

Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code in the server's JVM.

CVE-2018-19323
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
14.7%
2018 4 PoCs

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVE-2018-14667
🔥 KEV RichFaces General
9.8
CRITICAL
EPSS
89.5%
2018 CWE-94 7 PoCs

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVE-2018-6703
McAfee Agent Web
9.8
CRITICAL
EPSS
2.8%
2018 1 PoC

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.

CVE-2018-20753
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
37.7%
2018 2 PoCs

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

CVE-2018-2628
🔥 KEV WebLogic Server Database
9.8
CRITICAL
EPSS
94.4%
2018 26 PoCs

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).