Vulnerabilities in N/A
159,958 resultsCVE-2015-7501—Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise AppliEPSS 83.3%CVE-2016-0792—Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary codeEPSS 83.3%CVE-2020-7246—A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profileEPSS 83.2%CVE-2014-0050—MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attacEPSS 83.2%CVE-2010-4452—Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 EPSS 83.2%CVE-2018-9995—TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR LoginEPSS 83.2%CVE-2021-35392—Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binaEPSS 83.2%CVE-2019-7194CRITICALThis external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability,EPSS 83.1%KEVCVE-2021-27358—The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remotEPSS 83.0%CVE-2013-3861—Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash orEPSS 83.0%CVE-2020-3992CRITICALOpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a EPSS 83.0%KEVCVE-2016-5195HIGHRace condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haEPSS 83.0%KEVCVE-2018-17254—The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.EPSS 83.0%CVE-2022-42904HIGHZoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.EPSS 83.0%CVE-2019-14470—cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/sEPSS 83.0%CVE-2018-16763—FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth REPSS 82.9%CVE-2009-4006—Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0EPSS 82.9%CVE-2021-27561CRITICALYealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authenticatiEPSS 82.9%KEVCVE-2015-1187CRITICALThe ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.cEPSS 82.9%KEVCVE-2019-9514HIGHSome HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceEPSS 82.8%