Vulnerabilities in N/A
159,958 resultsCVE-2019-17270—Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemEPSS 58.9%CVE-2000-0574—FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the seEPSS 58.9%CVE-2012-4347—Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated EPSS 58.8%CVE-2013-1559—Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authEPSS 58.8%CVE-2003-0605—The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use EPSS 58.8%CVE-2006-1364—Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, EPSS 58.7%CVE-2023-27034CRITICALPrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.EPSS 58.7%CVE-2021-33393—lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by aEPSS 58.7%CVE-2020-11993—Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logginEPSS 58.7%CVE-2012-0432—Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an uEPSS 58.7%CVE-2020-24336—An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c dEPSS 58.7%CVE-2007-1373—Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitraryEPSS 58.7%CVE-2002-0654—Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a requesEPSS 58.7%CVE-2008-5619—html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2EPSS 58.6%CVE-2013-2068—Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to crEPSS 58.6%CVE-2023-28127HIGHA path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosuEPSS 58.6%CVE-2004-1305—The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote EPSS 58.6%CVE-2019-12347—In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accounEPSS 58.6%CVE-2016-6515—The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, whichEPSS 58.6%CVE-2021-44152—An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unaEPSS 58.6%