Vulnerabilities in N/A
159,958 resultsCVE-2022-42233CRITICALTenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.EPSS 42.7%CVE-2017-6862CRITICALNETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypEPSS 42.7%KEVCVE-2009-2477—js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackEPSS 42.7%CVE-2016-2171—The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attaEPSS 42.7%CVE-2009-1260—Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execEPSS 42.7%CVE-2010-1818—The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackersEPSS 42.7%CVE-2018-16752—LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping featEPSS 42.7%CVE-2018-0114—A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens uEPSS 42.7%CVE-2013-4710—Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView cEPSS 42.6%CVE-2011-1975—Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft WiEPSS 42.6%CVE-2012-3993—The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, ThunEPSS 42.6%CVE-2009-3028—The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, NotificationEPSS 42.6%CVE-2015-0231—Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.EPSS 42.6%CVE-1999-0891—The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.EPSS 42.6%CVE-2013-3630—Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then trEPSS 42.6%CVE-2011-0978—Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office CompatibiEPSS 42.6%CVE-2018-10736—A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.EPSS 42.6%CVE-2018-10737—A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.EPSS 42.6%CVE-2018-10738—A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.EPSS 42.6%CVE-2018-10735—A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.EPSS 42.6%