Vulnerabilities in N/A
159,958 resultsCVE-2020-26919CRITICALNETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.EPSS 57.2%KEVCVE-2008-0075—Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary codeEPSS 57.2%CVE-2019-5029CRITICALAn exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell EPSS 57.1%CVE-2008-0532—Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server EPSS 57.1%CVE-2021-28966—In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.EPSS 57.1%CVE-2023-23492HIGHThe Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' paramEPSS 57.1%CVE-2008-0027—Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CEPSS 57.1%CVE-2011-3497—service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibEPSS 57.1%CVE-2008-1083HIGHHeap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, ViEPSS 57.1%CVE-2008-1358—Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary coEPSS 57.1%CVE-2015-5259—Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to eEPSS 57.0%CVE-2022-37055CRITICALD-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,EPSS 57.0%KEVCVE-2019-5434—An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" paraEPSS 57.0%CVE-2005-1009—Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name EPSS 57.0%CVE-2008-0320—Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) andEPSS 57.0%CVE-2021-45428—TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files inEPSS 56.9%CVE-2009-2622—Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests includinEPSS 56.9%CVE-2022-28080—Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.EPSS 56.9%CVE-2017-6361—QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.EPSS 56.8%CVE-2013-3632HIGHThe Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrarEPSS 56.8%