Vulnerabilities in N/A
159,958 resultsCVE-2018-5999—An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requEPSS 87.3%CVE-2009-3555CRITICALThe TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thEPSS 87.3%CVE-2022-31814CRITICALpfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP HEPSS 87.2%CVE-2013-1488—The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execEPSS 87.2%CVE-2019-11358—jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypEPSS 87.2%CVE-2022-26143CRITICALThe TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers toEPSS 87.2%KEVCVE-2019-16057CRITICALThe login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.EPSS 87.2%KEVCVE-2018-9276HIGHAn issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console withEPSS 87.2%KEVCVE-2020-26948—Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.EPSS 87.2%CVE-2020-15867—The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if accEPSS 87.2%CVE-2015-3864—Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 EPSS 87.1%CVE-2021-41282—diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set inEPSS 87.1%CVE-2017-5487—wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not propEPSS 87.1%CVE-2022-31706CRITICALThe vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operatiEPSS 87.1%CVE-2014-4113HIGHwin32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7EPSS 87.0%KEVCVE-2016-6603—ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTPEPSS 87.0%CVE-2008-5416—Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SEPSS 87.0%CVE-2017-16894—In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct reEPSS 87.0%CVE-2005-2611—VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media ServeEPSS 87.0%CVE-2020-27988—Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).EPSS 87.0%