Vulnerabilities in N/A

159,958 results
CVE-2022-24632An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via theEPSS 27.4%CVE-2015-5958phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.EPSS 27.4%CVE-2017-16562The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authenticEPSS 27.4%CVE-2020-15906tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.EPSS 27.4%CVE-2020-35765doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQLEPSS 27.3%CVE-2002-0640Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses duEPSS 27.3%CVE-2023-36177CRITICALAn issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information EPSS 27.3%CVE-2011-3411Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handlinEPSS 27.3%CVE-2002-0936The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP EPSS 27.3%CVE-2012-3001Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command EPSS 27.3%CVE-2001-1325Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled EPSS 27.3%CVE-2002-0867Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet EEPSS 27.3%CVE-2016-0985Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR befEPSS 27.3%CVE-2018-7750transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.xEPSS 27.3%CVE-2016-2106Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote atEPSS 27.3%CVE-2020-11945An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resourceEPSS 27.2%CVE-2010-2889Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execEPSS 27.2%CVE-2024-25415HIGHA remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP EPSS 27.2%CVE-2008-4699Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrarEPSS 27.2%CVE-2023-31719FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.EPSS 27.2%