Vulnerabilities in N/A
160,044 resultsCVE-2014-3120HIGHThe default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expEPSS 88.6%KEVCVE-2004-1520—Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE commanEPSS 88.5%CVE-2021-40323—Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template iEPSS 88.5%CVE-2021-31643—An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a laEPSS 88.4%CVE-2020-8193MEDIUMImproper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and CEPSS 88.4%KEVCVE-2018-1000115—Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDPEPSS 88.4%CVE-2010-0188HIGHUnspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (aEPSS 88.2%KEVCVE-2012-1454—The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, FortinEPSS 88.2%CVE-2019-7192CRITICALThis improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, EPSS 88.2%KEVCVE-2004-2687—distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute aEPSS 88.2%CVE-2018-19207—The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code EPSS 88.1%CVE-2020-8772—The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attackerEPSS 88.0%CVE-2014-1776CRITICALUse-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denialEPSS 88.0%KEVCVE-2020-35729—KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.EPSS 88.0%CVE-2022-30781—Gitea before 1.16.7 does not escape git fetch remote.EPSS 87.9%CVE-2003-0085—Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, alEPSS 87.9%CVE-2014-0221—The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote aEPSS 87.9%CVE-2009-0658—Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafteEPSS 87.8%CVE-2022-31814CRITICALpfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP HEPSS 87.8%CVE-2020-17496CRITICALvBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panelEPSS 87.7%KEV