Vulnerabilities in N/A
159,958 resultsCVE-2021-20323—A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.EPSS 37.2%CVE-2022-24629CRITICALAn issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory trEPSS 37.2%CVE-2007-0221—Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (serEPSS 37.2%CVE-2014-3153HIGHThe futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresseEPSS 37.2%KEVCVE-2014-8686—CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption schEPSS 37.2%CVE-2013-4450—The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPEPSS 37.2%CVE-2008-0423—Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MYEPSS 37.2%CVE-2016-1106—Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer EPSS 37.2%CVE-2000-0854—When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msiEPSS 37.2%CVE-2017-12285—A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbEPSS 37.2%CVE-2018-11143—Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).EPSS 37.2%CVE-2011-4096—The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service EPSS 37.2%CVE-2008-0077—Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assEPSS 37.2%CVE-2012-0393—The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attacEPSS 37.2%CVE-2016-0099HIGHThe Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2EPSS 37.2%KEVCVE-2006-1300—Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bEPSS 37.2%CVE-2014-0118—The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decomprEPSS 37.2%CVE-2013-3868—Microsoft Active Directory Lightweight Directory Service (AD LDS) on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, aEPSS 37.1%CVE-2009-0220—Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 200EPSS 37.1%CVE-2022-27255—In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows anEPSS 37.1%