Vulnerabilities in N/A

159,958 results
CVE-2014-3936Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-50EPSS 76.6%CVE-2019-7238CRITICALSonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.EPSS 76.5%KEVCVE-2018-14728upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.EPSS 76.5%CVE-2018-12710An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilegEPSS 76.5%CVE-2015-8605ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crashEPSS 76.4%CVE-2010-2156ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length clEPSS 76.4%CVE-2013-0229The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denialEPSS 76.4%CVE-2003-0714The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) EPSS 76.4%CVE-2021-29156ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform characEPSS 76.4%CVE-2009-1979Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affectEPSS 76.4%CVE-2020-35951CRITICALAn issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wEPSS 76.3%CVE-2011-3556Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 EPSS 76.2%CVE-2018-8065An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncEPSS 76.2%CVE-2007-0042Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote EPSS 76.2%CVE-2013-1391Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR sysEPSS 76.1%CVE-2006-5745Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 onEPSS 76.1%CVE-2014-7141The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds reaEPSS 76.1%CVE-2002-1142Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and InterEPSS 76.0%CVE-2018-9160SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.EPSS 76.0%CVE-2013-5486Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1)EPSS 76.0%