Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-28 CVE-2015-5079 Path Traversal vulnerability in Blackcat-Cms Blackcat CMS
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a ..
network
low complexity
blackcat-cms CWE-22
7.5
2018-02-28 CVE-2015-4117 OS Command Injection vulnerability in Vestacp Control Panel
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
network
low complexity
vestacp CWE-78
8.8
2018-02-28 CVE-2016-0295 Cross-Site Request Forgery (CSRF) vulnerability in IBM Bigfix Platform
Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
network
low complexity
ibm CWE-352
8.8
2018-02-28 CVE-2016-0291 OS Command Injection vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access.
network
low complexity
ibm CWE-78
8.8
2018-02-28 CVE-2017-9447 Path Traversal vulnerability in Parallels Remote Application Server 15.5
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory.
network
low complexity
parallels CWE-22
7.5
2018-02-28 CVE-2017-12191 Unspecified vulnerability in Redhat Cloudforms 4.5
A flaw was found in the CloudForms account configuration when using VMware.
network
low complexity
redhat
7.4
2018-02-28 CVE-2018-7482 Path Traversal vulnerability in Joomlaworks K2 2.8.0
The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request.
network
low complexity
joomlaworks CWE-22
7.5
2018-02-27 CVE-2018-7549 Improper Input Validation vulnerability in multiple products
In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.
network
low complexity
zsh redhat canonical CWE-20
7.5
2018-02-27 CVE-2017-18205 NULL Pointer Dereference vulnerability in ZSH Project ZSH
In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.
network
high complexity
zsh-project CWE-476
8.1
2018-02-27 CVE-2014-10070 Permissions, Privileges, and Access Controls vulnerability in ZSH Project ZSH
zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers).
local
low complexity
zsh-project CWE-264
7.8