Vulnerabilities in N/A
159,958 resultsCVE-2018-16042—Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earEPSS 82.4%CVE-2011-0276—HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager EPSS 82.4%CVE-2010-1297HIGHAdobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,EPSS 82.4%KEVCVE-2014-1510—The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 EPSS 82.3%CVE-2021-26120—Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.EPSS 82.3%CVE-2019-7254—Linear eMerge E3-Series devices allow File Inclusion.EPSS 82.3%CVE-2023-20888HIGHAria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria OEPSS 82.3%CVE-2018-10660—An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.EPSS 82.3%CVE-2009-2521—Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticaEPSS 82.3%CVE-2024-46538CRITICALA cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadEPSS 82.3%CVE-2011-2140—Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 oEPSS 82.3%CVE-2020-9465—An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowingEPSS 82.2%CVE-2003-0818—Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and lEPSS 82.2%CVE-2014-9016—The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal alloEPSS 82.2%CVE-2010-0806HIGHUse-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote atEPSS 82.2%KEVCVE-2020-17505—Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These cEPSS 82.2%CVE-2023-48646—Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.EPSS 82.2%CVE-2023-41266HIGHA path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 aEPSS 82.1%KEVCVE-2016-0800—The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify meEPSS 82.1%CVE-2015-6922—Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not proEPSS 82.1%