Vulnerabilities in N/A
159,958 resultsCVE-2020-13934—An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 procesEPSS 64.1%CVE-2023-41109—SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.EPSS 64.1%CVE-2018-1000207—MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phptEPSS 64.1%CVE-2011-1565—Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSSEPSS 64.1%CVE-2012-0299—The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codeEPSS 64.1%CVE-2021-36450—Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.EPSS 64.0%CVE-2007-2939—Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL EPSS 64.0%CVE-2023-42326—An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php EPSS 64.0%CVE-2006-3726—Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to execute arbitrary coEPSS 64.0%CVE-2012-5067—Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers tEPSS 64.0%CVE-2009-3711—Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a dEPSS 63.9%CVE-2014-5350—Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files viaEPSS 63.9%CVE-2005-0308—Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import orEPSS 63.9%CVE-2006-5000—Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote autEPSS 63.8%CVE-2009-2936—The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before EPSS 63.8%CVE-2006-3730HIGHInteger overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and executeEPSS 63.8%CVE-2018-18852—Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING featureEPSS 63.8%CVE-2019-6447—The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute appliEPSS 63.8%CVE-2019-14287—In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, aEPSS 63.8%CVE-2014-9222—AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gaEPSS 63.7%