Vulnerabilidades en n/a
160.875 resultadosCVE-2020-5514—Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.EPSS 44.1%CVE-2021-31586—Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.EPSS 44.1%CVE-2018-15517—The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actEPSS 44.1%CVE-2017-17733—Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.EPSS 44.1%CVE-2002-0422—IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured byEPSS 44.1%CVE-2015-3194—crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL poiEPSS 44.0%CVE-2006-2842—PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_EPSS 44.0%CVE-2012-4933—The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hardEPSS 44.0%CVE-2007-0024—Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 EPSS 44.0%CVE-2019-12583—Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guestEPSS 43.9%CVE-2008-0016—Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote aEPSS 43.9%CVE-2005-4145—The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search spaceEPSS 43.9%CVE-2007-0612—Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet ExplEPSS 43.9%CVE-2013-4115—Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to EPSS 43.9%CVE-2025-32813HIGHAn issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.EPSS 43.9%CVE-2000-0413—The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML,EPSS 43.9%CVE-2020-13693—An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.EPSS 43.9%CVE-2021-20235—There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sizeEPSS 43.9%CVE-2019-10662—Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backEPSS 43.9%CVE-2014-0198—The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a bEPSS 43.8%