Vulnerabilities in N/A
159,958 resultsCVE-2018-20434—LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.EPSS 71.5%CVE-2003-0264—Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe,EPSS 71.5%CVE-2016-3247—Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corrEPSS 71.5%CVE-2008-4828—Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thrEPSS 71.5%CVE-2019-19985MEDIUMThe WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user informatEPSS 71.4%CVE-2021-46419—An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.EPSS 71.4%CVE-2010-2703—Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when EPSS 71.4%CVE-2006-2407—Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreEPSS 71.4%CVE-2011-3400—Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute EPSS 71.4%CVE-2020-10819—Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.EPSS 71.3%CVE-2018-17532—Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autoloEPSS 71.3%CVE-2006-0295—Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbiEPSS 71.3%CVE-2006-4305—Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connectEPSS 71.3%CVE-2013-4811—UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity DriEPSS 71.3%CVE-2016-1909—Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.EPSS 71.3%CVE-2001-0540—Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via EPSS 71.2%CVE-2022-28379MEDIUMjc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.EPSS 71.2%CVE-2002-0079—Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attacEPSS 71.2%CVE-2012-4959—Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 13EPSS 71.2%CVE-2007-3371—PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PEPSS 71.2%