Vulnerabilities in N/A
159,958 resultsCVE-2002-0568—Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information iEPSS 75.2%CVE-2019-10267—An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into aEPSS 75.2%CVE-2015-1497—radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commandEPSS 75.1%CVE-2019-20215—D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in EPSS 75.1%CVE-2017-9248CRITICALTelerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect TeEPSS 75.1%KEVCVE-2009-2629—Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.EPSS 75.1%CVE-2012-0391CRITICALThe ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception haEPSS 75.1%KEVCVE-2014-9390—Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforeEPSS 75.0%CVE-2015-1592—Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::tEPSS 75.0%CVE-2006-3942—The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (sysEPSS 75.0%CVE-2016-1525—Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticatEPSS 75.0%CVE-2006-0476—Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (FEPSS 75.0%CVE-2020-35848—Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.EPSS 75.0%CVE-2021-25298HIGHNagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/confiEPSS 75.0%KEVCVE-2013-0803—A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.EPSS 75.0%CVE-2005-0116—AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir EPSS 74.9%CVE-2009-0920—Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers tEPSS 74.9%CVE-2014-4977—Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commanEPSS 74.9%CVE-2023-35885CRITICALCloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.EPSS 74.9%CVE-2015-2080—The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memEPSS 74.9%