Vulnerabilities in N/A
159,958 resultsCVE-2007-3325—PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execEPSS 64.4%CVE-2007-3306—PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code vEPSS 64.4%CVE-2007-2937—PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL iEPSS 64.4%CVE-2022-44149HIGHThe web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd inEPSS 64.4%CVE-2014-7186—The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-boEPSS 64.3%CVE-2014-6277—GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attEPSS 64.3%CVE-2018-15727—Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember EPSS 64.3%CVE-2019-6977—gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.EPSS 64.3%CVE-2018-19422—/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess fiEPSS 64.3%CVE-2018-7297—Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/writEPSS 64.3%CVE-2010-3072—The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial ofEPSS 64.2%CVE-2011-0922—The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share EPSS 64.2%CVE-2007-3524—Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHPEPSS 64.2%CVE-2023-34039CRITICALAria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicioEPSS 64.2%CVE-2014-3789—GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspeciEPSS 64.2%CVE-2018-8735—Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commandsEPSS 64.2%CVE-2021-27212—In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function viEPSS 64.1%CVE-2020-36243—The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulneraEPSS 64.1%CVE-2016-1593—Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated admiEPSS 64.1%CVE-2017-11165—dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for thEPSS 64.1%