Show filters
812 Total Results
Displaying 81-90 of 812
Sort by:
Attacker Value
Very High

CVE-2023-45249

Disclosure Date: July 24, 2024 (last updated July 27, 2024)
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
Attacker Value
Very High

CVE-2017-10271 - Oracle WebLogic Server AsyncResponseService Deserialization Vu…

Disclosure Date: October 19, 2017 (last updated July 25, 2024)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Attacker Value
Very High

CVE-2022-30995

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.
Attacker Value
Very High

CVE-2022-31814

Disclosure Date: September 05, 2022 (last updated May 15, 2024)
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
Attacker Value
High

CVE-2023-21768

Disclosure Date: January 10, 2023 (last updated January 11, 2025)
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Attacker Value
Very High

CVE-2024-22729

Disclosure Date: January 25, 2024 (last updated February 02, 2024)
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
Attacker Value
Unknown

MS15-134 Microsoft Office COM Object DLL Planting with els.dll

Disclosure Date: December 09, 2015 (last updated October 05, 2023)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."
0
Attacker Value
Very High

CVE-2023-30013

Disclosure Date: May 05, 2023 (last updated October 08, 2023)
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
Attacker Value
High

CVE-2021-1497

Disclosure Date: May 05, 2021 (last updated July 26, 2024)
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Attacker Value
Low

CVE-2022-26871

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.