Vulnerabilities in N/A
159,958 resultsCVE-2020-8163—The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument oEPSS 82.0%CVE-2016-0742—The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereferenceEPSS 82.0%CVE-2014-8440—Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR befEPSS 81.9%CVE-2009-4324HIGHUse-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before EPSS 81.9%KEVCVE-2017-8779—rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data EPSS 81.9%CVE-2023-26469—In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.EPSS 81.9%CVE-2020-35578—An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled durinEPSS 81.9%CVE-2016-10372—The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP portEPSS 81.9%CVE-2009-2526—Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remotEPSS 81.9%CVE-2020-7200—A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploiteEPSS 81.9%CVE-2015-6128—Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gaEPSS 81.9%CVE-2013-1331HIGHBuffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data EPSS 81.9%KEVCVE-2013-0074HIGHMicrosoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, whichEPSS 81.9%KEVCVE-2017-1001000—The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before EPSS 81.8%CVE-2015-1868—The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) ServerEPSS 81.8%CVE-2020-9315—** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the AdmiEPSS 81.8%CVE-2023-43177—CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.EPSS 81.8%CVE-2004-1172—Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, aEPSS 81.8%CVE-2007-1036—The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackEPSS 81.8%CVE-2015-7871—Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.EPSS 81.8%