Vulnerabilities in N/A
159,958 resultsCVE-2013-2088—contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute aEPSS 31.5%CVE-2010-2951—dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which alloEPSS 31.5%CVE-2006-6456—Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecifieEPSS 31.4%CVE-2020-23972—In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application aEPSS 31.4%CVE-2012-3137—The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackersEPSS 31.4%CVE-2013-1325—Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerEPSS 31.4%CVE-2013-1324—Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute aEPSS 31.4%CVE-2013-5912—VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via EPSS 31.4%CVE-2019-9041—An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, rEPSS 31.4%CVE-2019-7669—Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticEPSS 31.4%CVE-2014-1683—The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid paEPSS 31.4%CVE-1999-0678—A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation filesEPSS 31.4%CVE-2006-0034—Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction CoordinatEPSS 31.4%CVE-2023-26613—An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operatiEPSS 31.4%CVE-2016-4523HIGHThe WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (EPSS 31.4%KEVCVE-2009-4265—Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary coEPSS 31.4%CVE-2021-37589—Virtua Cobranca before 12R allows SQL Injection on the login page.EPSS 31.4%CVE-2007-5363—PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for JoomlEPSS 31.4%CVE-2007-5841—PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary PHP code via a URL inEPSS 31.4%CVE-2009-4962—Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: soEPSS 31.4%