Vulnerabilities in N/A
159,958 resultsCVE-2020-27615—The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ipEPSS 52.3%CVE-2020-25108—An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked (it can be set to aEPSS 52.3%CVE-2020-25110—An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is notEPSS 52.3%CVE-2020-25107—An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name has '\0' terminationEPSS 52.3%CVE-2020-25109—An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is noEPSS 52.3%CVE-2019-8953—The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lisEPSS 52.2%CVE-2019-13272HIGHIn the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creEPSS 52.2%KEVCVE-2015-0925—The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a EPSS 52.2%CVE-2002-0147—Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause aEPSS 52.2%CVE-2021-33032—A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 anEPSS 52.2%CVE-2019-7232—The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflowEPSS 52.1%CVE-2022-31470—An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 1EPSS 52.1%CVE-2008-3013—gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, EPSS 52.1%CVE-2018-25032HIGHzlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.EPSS 52.1%CVE-2020-11547—PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itEPSS 52.1%CVE-2023-32782—A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with wriEPSS 52.1%CVE-2022-44792MEDIUMhandle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used byEPSS 52.1%CVE-2021-28114—Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.EPSS 52.0%CVE-2008-1898—A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remoteEPSS 52.0%CVE-2012-3951—The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (EPSS 52.0%