Vulnerabilities in N/A
159,958 resultsCVE-2007-2199—PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcEPSS 46.8%CVE-2023-37580MEDIUMZimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.EPSS 46.7%KEVCVE-2017-16943—The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a EPSS 46.7%CVE-2005-0050—The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of mesEPSS 46.7%CVE-2007-4677—Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size wEPSS 46.7%CVE-2007-4676—Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsiEPSS 46.7%CVE-2020-8958—Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers toEPSS 46.6%CVE-2019-9879—The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratioEPSS 46.6%CVE-2016-3976HIGHDirectory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot doEPSS 46.6%KEVCVE-2007-5000—Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61EPSS 46.6%CVE-2007-0045—Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with AdEPSS 46.6%CVE-2005-0051—The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing rEPSS 46.6%CVE-2002-0597—LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malforEPSS 46.6%CVE-2018-15812—DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.EPSS 46.5%CVE-2012-6275—Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impaEPSS 46.5%CVE-2006-5028—Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remotEPSS 46.5%CVE-2007-5842—Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary PHP code via a URL inEPSS 46.5%CVE-2020-8771—The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client EPSS 46.5%CVE-2009-0043—The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict accesEPSS 46.5%CVE-2022-39197MEDIUMAn XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTMEPSS 46.4%KEV