Vulnerabilities in N/A
159,958 resultsCVE-2020-5505—Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"applicEPSS 44.3%CVE-2005-3792—Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows rEPSS 44.3%CVE-2008-4726—Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbitrary code via a longEPSS 44.3%CVE-2014-3506—d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers tEPSS 44.2%CVE-2008-1060—Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute EPSS 44.2%CVE-2016-2182—The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attaEPSS 44.2%CVE-2015-1587—Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote atEPSS 44.2%CVE-2007-4474—Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dllEPSS 44.2%CVE-2023-24709HIGHAn issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.EPSS 44.2%CVE-2019-14928—An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of storEPSS 44.1%CVE-2000-0951—A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web roEPSS 44.1%CVE-2024-55556CRITICALA vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on thEPSS 44.1%CVE-2020-5514—Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.EPSS 44.1%CVE-2021-31586—Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.EPSS 44.1%CVE-2018-15517—The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actEPSS 44.1%CVE-2017-17733—Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.EPSS 44.1%CVE-2006-2842—PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_EPSS 44.0%CVE-2015-3194—crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL poiEPSS 44.0%CVE-2012-4933—The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hardEPSS 44.0%CVE-2007-0024—Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 EPSS 44.0%