Vulnerabilidades en n/a
160.875 resultadosCVE-2018-16299—The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.EPSS 44.4%CVE-2018-16117—A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackerEPSS 44.3%CVE-2024-48307CRITICALJeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.EPSS 44.3%CVE-2018-11510—The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgEPSS 44.3%CVE-2020-5505—Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"applicEPSS 44.3%CVE-2005-3792—Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows rEPSS 44.3%CVE-2021-42887—In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.EPSS 44.3%CVE-2012-2611—The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeavEPSS 44.3%CVE-2008-4726—Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbitrary code via a longEPSS 44.3%CVE-2008-1609—Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PEPSS 44.3%CVE-2008-1060—Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute EPSS 44.2%CVE-2016-2182—The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attaEPSS 44.2%CVE-2012-3815—Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackerEPSS 44.2%CVE-2015-1587—Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote atEPSS 44.2%CVE-2007-4474—Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dllEPSS 44.2%CVE-2023-24709HIGHAn issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.EPSS 44.2%CVE-2019-14928—An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of storEPSS 44.1%CVE-2000-0951—A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web roEPSS 44.1%CVE-2024-55556CRITICALA vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on thEPSS 44.1%CVE-2012-1775—Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS://EPSS 44.1%