Vulnerabilities in N/A
159,958 resultsCVE-2023-23074MEDIUMCross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.EPSS 83.6%CVE-2022-24990CRITICALTerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/aEPSS 83.5%KEVCVE-2022-29081—Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-controEPSS 83.5%CVE-2007-4560—clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharEPSS 83.5%CVE-2012-0151HIGHThe Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows SeEPSS 83.5%KEVCVE-2010-2075—UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modificatEPSS 83.5%CVE-2017-11317CRITICALTelerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which aEPSS 83.5%KEVCVE-2005-1790—Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of servicEPSS 83.5%CVE-2009-2288—statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) TEPSS 83.5%CVE-2016-10174CRITICALThe NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. EPSS 83.5%KEVCVE-2019-9512HIGHSome HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of serviceEPSS 83.4%CVE-2016-10134—SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the tEPSS 83.4%CVE-2001-1583—lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control EPSS 83.4%CVE-2014-7863—The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 1EPSS 83.4%CVE-2010-1871HIGHJBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for EPSS 83.4%KEVCVE-2008-6508—Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypEPSS 83.4%CVE-2020-36228—An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, rEPSS 83.4%CVE-2009-3733—Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.EPSS 83.4%CVE-2016-0041—Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1EPSS 83.3%CVE-2010-3765CRITICALMozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x befEPSS 83.3%KEV