Vulnerabilities in N/A

159,958 results
CVE-2018-7700DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specifyEPSS 74.5%CVE-2020-24391mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-EPSS 74.5%CVE-2015-0779Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote aEPSS 74.5%CVE-2012-5159phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introducedEPSS 74.5%CVE-2015-5374A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant MoEPSS 74.5%CVE-2021-37538Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execEPSS 74.5%CVE-2015-1789The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1EPSS 74.5%CVE-2019-13345The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.EPSS 74.5%CVE-2015-3043HIGHAdobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attEPSS 74.4%KEVCVE-2018-17243Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.EPSS 74.4%CVE-2012-0394The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrarEPSS 74.4%CVE-2008-1697Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers toEPSS 74.3%CVE-2020-10188utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becausEPSS 74.3%CVE-2020-12109Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, EPSS 74.3%CVE-2015-3087Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460EPSS 74.3%CVE-2018-19300On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware versionEPSS 74.3%CVE-2023-23076CRITICALOS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.EPSS 74.3%CVE-2013-3336Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.EPSS 74.3%CVE-2016-1561ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attaEPSS 74.3%CVE-2005-2297Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary codEPSS 74.2%