Vulnerabilities in N/A

159,958 results
CVE-2022-26148An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML EPSS 53.4%CVE-2011-0104Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to exEPSS 53.4%CVE-2016-2211The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 EPSS 53.4%CVE-2018-17281There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x EPSS 53.4%CVE-2005-1978COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbiEPSS 53.4%CVE-2005-2847img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metachaEPSS 53.4%CVE-2014-9118The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacEPSS 53.4%CVE-2014-0644EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML EPSS 53.3%CVE-2015-7007Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execuEPSS 53.3%CVE-2006-2502Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers tEPSS 53.3%CVE-2006-5702Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1)EPSS 53.3%CVE-2023-27823CRITICALAn authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.EPSS 53.3%CVE-1999-0191IIS newdsn.exe CGI script allows remote users to overwrite files.EPSS 53.3%CVE-2002-0072The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not propEPSS 53.3%CVE-2018-8734SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrarEPSS 53.2%CVE-2024-37843HIGHCraft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.EPSS 53.2%CVE-2023-24078HIGHReal Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmEPSS 53.2%CVE-2022-23940SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module EPSS 53.2%CVE-2022-24562In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access tEPSS 53.2%CVE-2015-1642HIGHMicrosoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft OEPSS 53.2%KEV