Vulnerabilities in N/A

159,958 results
CVE-2016-3718MEDIUMThe (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request EPSS 76.9%KEVCVE-2023-22621CRITICALStrapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the serveEPSS 76.8%CVE-2018-15133HIGHIn Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a poteEPSS 76.8%KEVCVE-2016-3236The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SPEPSS 76.8%CVE-2020-10173Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and EPSS 76.8%CVE-2020-13638lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue hEPSS 76.8%CVE-2003-0190OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, whichEPSS 76.8%CVE-2017-9101import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header aEPSS 76.7%CVE-2008-0015HIGHStack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequesEPSS 76.7%KEVCVE-2017-9554An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers EPSS 76.7%CVE-2009-2685Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary EPSS 76.7%CVE-2010-3600Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager GriEPSS 76.7%CVE-2007-5423tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, whichEPSS 76.7%CVE-2021-35478Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used EPSS 76.6%CVE-2020-28347tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NEPSS 76.6%CVE-2022-45699CRITICALCommand injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrEPSS 76.6%CVE-2005-3081wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command.EPSS 76.6%CVE-2020-13965MEDIUMAn issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/EPSS 76.6%KEVCVE-2022-44267MEDIUMImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waEPSS 76.6%CVE-2000-0649IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected byEPSS 76.6%