Vulnerabilities in N/A

159,958 results
CVE-2018-0824HIGHA remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "MicrosEPSS 72.4%KEVCVE-2014-3804The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_EPSS 72.4%CVE-2013-3623Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Management Interface (IPMI) wEPSS 72.4%CVE-2021-3197An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommEPSS 72.3%CVE-2004-1134Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitraryEPSS 72.3%CVE-2016-1560ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for theEPSS 72.3%CVE-2021-33564An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files EPSS 72.2%CVE-2023-36933In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is EPSS 72.2%CVE-2014-0307Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of serviceEPSS 72.2%CVE-2006-5156Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbiEPSS 72.2%CVE-2009-1943Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitraryEPSS 72.2%CVE-2002-1337Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tEPSS 72.2%CVE-2017-6334HIGHdnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands EPSS 72.2%KEVCVE-2014-0514The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to eEPSS 72.2%CVE-2010-1553Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to eEPSS 72.2%CVE-2006-7196Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0EPSS 72.2%CVE-2019-16724File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) basEPSS 72.2%CVE-2004-1315viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, whicEPSS 72.1%CVE-2019-8903index.js in Total.js Platform before 3.2.3 allows path traversal.EPSS 72.1%CVE-2021-30117CRITICALAuthenticated SQL injection in Kaseya VSA < v9.5.6EPSS 72.1%