Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2019-9874
Known exploited
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
CVSS Score
9.8
EPSS Score
0.251
Published
2019-05-31
CVE-2019-9875
Known exploited
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
CVSS Score
8.8
EPSS Score
0.142
Published
2019-05-31
CVE-2019-9670
Known exploited
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
CVSS Score
9.8
EPSS Score
0.944
Published
2019-05-29
CVE-2018-13383
Known exploited
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
CVSS Score
4.3
EPSS Score
0.011
Published
2019-05-29
CVE-2018-7841
Known exploited
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
CVSS Score
9.8
EPSS Score
0.591
Published
2019-05-22
CVE-2019-11634
Known exploited
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CVSS Score
9.8
EPSS Score
0.562
Published
2019-05-22
CVE-2019-0903
Known exploited
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
CVSS Score
8.8
EPSS Score
0.507
Published
2019-05-16
CVE-2019-0708
Known exploited
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CVSS Score
9.8
EPSS Score
0.944
Published
2019-05-16
CVE-2019-0863
Known exploited
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
CVSS Score
7.8
EPSS Score
0.142
Published
2019-05-16
CVE-2018-14839
Known exploited
LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.
CVSS Score
9.8
EPSS Score
0.917
Published
2019-05-14


Contact Us

Shodan ® - All rights reserved