Vulnerabilities in N/A

160,044 results
CVE-2015-7857SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 beEPSS 93.9%CVE-2024-55956CRITICALIn Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitEPSS 93.8%KEVCVE-2013-0625CRITICALAdobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeEPSS 93.8%KEVCVE-2016-0189HIGHThe Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remoEPSS 93.7%KEVCVE-2013-0632CRITICALadministrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrEPSS 93.7%KEVCVE-2012-1723CRITICALUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,EPSS 93.7%KEVCVE-2015-5122HIGHUse-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0EPSS 93.7%KEVCVE-2012-1433The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus UtilEPSS 93.6%CVE-2012-1435The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus UtilEPSS 93.6%CVE-2012-1436The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus UtilEPSS 93.6%CVE-2013-1965Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL codeEPSS 93.4%CVE-2012-1432The Microsoft EXE file parser in Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, andEPSS 93.4%CVE-2018-6892An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client applicatiEPSS 93.4%CVE-2019-7276Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.EPSS 93.4%CVE-2017-14492Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viaEPSS 93.3%CVE-2023-48795MEDIUMThe SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasEPSS 93.3%CVE-2021-44077CRITICALZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unEPSS 93.3%KEVCVE-2016-7552On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthentEPSS 93.2%CVE-2020-5849HIGHUnraid 6.8.0 allows authentication bypass.EPSS 93.2%KEVCVE-2020-35846Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.EPSS 93.2%