Vulnerabilities in N/A
159,958 resultsCVE-2019-8457—SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tEPSS 45.4%CVE-2021-29003—Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valiEPSS 45.4%CVE-2023-43187—A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackersEPSS 45.4%CVE-2008-5764—PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to exEPSS 45.4%CVE-2019-18952—SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote cEPSS 45.4%CVE-2007-2484—PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globalEPSS 45.4%CVE-2014-9312—Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.EPSS 45.4%CVE-2018-15839—D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.EPSS 45.3%CVE-2008-4557—plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code vEPSS 45.3%CVE-2004-0460—Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause EPSS 45.3%CVE-2004-0201—Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allEPSS 45.3%CVE-2019-5127CRITICALA command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. ExploitableEPSS 45.3%CVE-2018-15535—/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be withiEPSS 45.2%CVE-2020-11798—A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow anEPSS 45.2%CVE-2022-21826—Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request,EPSS 45.2%CVE-2020-35313—A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remEPSS 45.2%CVE-2011-2386—VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary coEPSS 45.2%CVE-2019-12384—FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-EPSS 45.2%CVE-2013-0209—lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migrEPSS 45.2%CVE-2004-0595—The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restrictiEPSS 45.2%