Vulnerabilidades en n/a
160.786 resultadosCVE-2019-20085HIGHTVT NVMS-1000 devices allow GET /.. Directory TraversalEPSS 96.1%KEVCVE-2022-36446—software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.EPSS 96.0%CVE-2015-4852CRITICALThe WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitraryEPSS 96.0%KEVCVE-2012-1430—The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning EEPSS 96.0%CVE-2012-1431—The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-SecEPSS 96.0%CVE-2014-6321—Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,EPSS 96.0%CVE-2020-5847CRITICALUnraid through 6.8.0 allows Remote Code Execution.EPSS 95.8%KEVCVE-2021-31806—An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service aEPSS 95.8%CVE-2020-12256—rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafEPSS 95.8%CVE-1999-0016—Land IP denial of service.EPSS 95.7%CVE-2016-2183HIGHThe DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprEPSS 95.7%CVE-2020-11530—A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameterEPSS 95.7%CVE-2016-0752HIGHDirectory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, anEPSS 95.5%KEVCVE-2022-41352CRITICALAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophEPSS 95.5%KEVCVE-2020-13167—Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) laEPSS 95.4%CVE-2022-36537HIGHZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent EPSS 95.4%KEVCVE-2011-0049—Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers EPSS 95.4%CVE-2020-14144—The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the doEPSS 95.4%CVE-2019-20499—D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionalitEPSS 95.3%CVE-2013-0333—lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data toEPSS 95.3%