Vulnerabilities in n/a

160,858 results
CVE-2019-19006CRITICALSangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.EPSS 55.9%KEVCVE-2007-0046—Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to exEPSS 55.9%CVE-2015-1701HIGHWin32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privilEPSS 55.9%KEVCVE-2006-3280—Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains viEPSS 55.9%CVE-2008-3704—Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in MicEPSS 55.9%CVE-2007-0044—Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the broEPSS 55.9%CVE-2019-18371—An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary EPSS 55.9%CVE-2025-26319CRITICALFlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.EPSS 55.9%CVE-2018-19206—steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elemEPSS 55.9%CVE-2019-7255—Linear eMerge E3-Series devices allow XSS.EPSS 55.8%CVE-2019-14322—In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.EPSS 55.8%CVE-2011-3494—WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary codeEPSS 55.8%CVE-2013-0025—Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that EPSS 55.8%CVE-2016-5387—The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untruEPSS 55.7%CVE-2019-8387—MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.EPSS 55.7%CVE-2005-2124—Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to EPSS 55.7%CVE-2021-21745—ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to EPSS 55.7%CVE-2013-3520—VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary EPSS 55.6%CVE-2014-7236—Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the deEPSS 55.6%CVE-2010-1423—Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and otEPSS 55.6%