Vulnerabilities in N/A
159,958 resultsCVE-2021-40410CRITICALAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] thEPSS 27.9%CVE-2018-15531—JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.EPSS 27.9%CVE-2007-5056—Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPEPSS 27.9%CVE-1999-0002—Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.EPSS 27.9%CVE-2018-9032—An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; FirmwarEPSS 27.8%CVE-2010-4741—Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to executEPSS 27.8%CVE-2017-14335—On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/SecuriEPSS 27.8%CVE-2018-14707—Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload fEPSS 27.8%CVE-2010-2330—Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly eEPSS 27.8%CVE-2009-0184—Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote EPSS 27.8%CVE-2020-24397—An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an EPSS 27.8%CVE-2010-4566—The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTEPSS 27.8%CVE-2021-22146—All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the defaulEPSS 27.8%CVE-2006-5752—Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabEPSS 27.8%CVE-2008-1145—Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems EPSS 27.8%CVE-2011-2003—Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, WiEPSS 27.8%CVE-2020-28976—The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any inEPSS 27.8%CVE-2016-0060—Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (mEPSS 27.8%CVE-2008-2752—Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to EPSS 27.8%CVE-2023-22960HIGHLexmark products through 2023-01-10 have Improper Control of Interaction Frequency.EPSS 27.8%