Vulnerabilities in N/A

159,958 results
CVE-2016-8870The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registrEPSS 81.2%CVE-2003-0719Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft WinEPSS 81.2%CVE-2020-25681A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating EPSS 81.2%CVE-2017-10974Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only aboutEPSS 81.2%CVE-2011-5034Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predicEPSS 81.2%CVE-2015-3827The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relatioEPSS 81.1%CVE-2023-36932In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023EPSS 81.1%CVE-2011-0923The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code EPSS 81.1%CVE-2013-4212Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expreEPSS 81.1%CVE-2014-7862The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create adEPSS 81.0%CVE-2003-0812Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary EPSS 81.0%CVE-2022-31704CRITICALThe vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into seEPSS 81.0%CVE-2014-3829displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execuEPSS 81.0%CVE-2018-5955An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attackerEPSS 81.0%CVE-2016-7255HIGHThe kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 EPSS 81.0%KEVCVE-2019-9621HIGHZimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3EPSS 80.9%KEVCVE-2005-2535Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commandEPSS 80.9%CVE-2007-6203Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "4EPSS 80.7%CVE-2010-3552Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to aEPSS 80.7%CVE-2014-9583common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and otEPSS 80.7%