Vulnerabilities in N/A

159,958 results
CVE-2019-10669An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.phpEPSS 80.7%CVE-2015-7766PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions viEPSS 80.6%CVE-2015-7808The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection aEPSS 80.6%CVE-2010-0805The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remoteEPSS 80.6%CVE-2020-13160AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.EPSS 80.6%CVE-2008-4397Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 throuEPSS 80.5%CVE-2016-3087Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackerEPSS 80.5%CVE-2010-0361Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attEPSS 80.5%CVE-2013-3183The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012,EPSS 80.5%CVE-2015-2545HIGHMicrosoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, akEPSS 80.5%KEVCVE-2013-4123client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafteEPSS 80.5%CVE-2011-4858Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the abiliEPSS 80.3%CVE-2008-0244SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in execEPSS 80.3%CVE-2023-39143CRITICALPaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. ThEPSS 80.3%CVE-2004-0230TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectioEPSS 80.3%CVE-2023-22952HIGHIn SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input valiEPSS 80.3%KEVCVE-2003-0349Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft WindowsEPSS 80.3%CVE-2007-5365Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementatiEPSS 80.3%CVE-2002-1359Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial oEPSS 80.2%CVE-2020-8821An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML codEPSS 80.2%