Vulnerabilities in N/A
159,958 resultsCVE-2018-20526—Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.EPSS 73.1%CVE-2005-2428—Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, whiEPSS 73.0%CVE-2007-1697—PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code EPSS 73.0%CVE-2004-0204—Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used EPSS 73.0%CVE-2019-10072—The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1EPSS 73.0%CVE-2018-1000533—klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` functioEPSS 73.0%CVE-2008-0356—Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 aEPSS 73.0%CVE-2019-9978MEDIUMThe social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameterEPSS 72.9%KEVCVE-2020-5741HIGHDeserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.EPSS 72.9%KEVCVE-2016-0117—The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackEPSS 72.9%CVE-2024-0352HIGHLikeshop HTTP POST Request File.php userFormImage unrestricted uploadEPSS 72.9%CVE-2007-0038—Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitEPSS 72.9%CVE-2020-27386—An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary filEPSS 72.9%CVE-2007-1674—Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitraryEPSS 72.9%CVE-2019-0199—The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS framesEPSS 72.9%CVE-2012-0262—op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrarEPSS 72.9%CVE-2006-0992—Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a lEPSS 72.8%CVE-2013-2115—Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled whEPSS 72.8%CVE-2014-6038—Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLoEPSS 72.8%CVE-2014-3828—Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attacEPSS 72.7%