Vulnerabilities in n/a

160,843 results
CVE-2010-2550—The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and REPSS 75.7%CVE-2004-0847—The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricteEPSS 75.7%CVE-2014-9735—The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does EPSS 75.7%CVE-2011-2371—Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMEPSS 75.7%CVE-2007-0940—Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM anEPSS 75.7%CVE-2010-2729—The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold,EPSS 75.6%CVE-2018-9160—SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.EPSS 75.6%CVE-2012-0391CRITICALThe ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception haEPSS 75.6%KEVCVE-2014-9390—Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforeEPSS 75.6%CVE-2022-32429—An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNEPSS 75.6%CVE-2010-3275—libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an EPSS 75.5%CVE-2004-2086—Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of EPSS 75.5%CVE-2015-2080—The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memEPSS 75.4%CVE-2015-1592—Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::tEPSS 75.4%CVE-2020-28347—tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NEPSS 75.4%CVE-2021-31856—A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimeEPSS 75.4%CVE-2023-3643HIGHBoss Mini document file inclusionEPSS 75.4%CVE-2017-17850—An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP meEPSS 75.4%CVE-2020-25540—ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via EPSS 75.3%CVE-2021-3007—Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execuEPSS 75.3%