Vulnerabilities in N/A
159,958 resultsCVE-2022-24313—A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leadinEPSS 44.6%CVE-2013-1892—MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows rEPSS 44.5%CVE-2016-2177—OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a deEPSS 44.5%CVE-2015-0292—Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1EPSS 44.5%CVE-2005-1987—Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to EPSS 44.5%CVE-2016-3301—The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012EPSS 44.5%CVE-2008-3479—Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackersEPSS 44.5%CVE-2012-2626—cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authenticatiEPSS 44.5%CVE-2007-0446—Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1EPSS 44.5%CVE-2007-3101—Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackeEPSS 44.5%CVE-2007-2167—Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the numberEPSS 44.4%CVE-2015-5562—Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK beforeEPSS 44.4%CVE-2021-35042—Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a wEPSS 44.4%CVE-2007-3111—Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4,EPSS 44.4%CVE-2019-13635—The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.EPSS 44.4%CVE-2006-5085—Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nEPSS 44.4%CVE-2018-16299—The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.EPSS 44.4%CVE-2024-48307CRITICALJeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.EPSS 44.3%CVE-2018-16117—A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackerEPSS 44.3%CVE-2012-3815—Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackerEPSS 44.3%