Vulnerabilidades en n/a
160.793 resultadosCVE-2023-48795MEDIUMThe SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasEPSS 93.3%CVE-2021-44077CRITICALZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unEPSS 93.3%KEVCVE-2020-35846—Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.EPSS 93.3%CVE-2016-7552—On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthentEPSS 93.2%CVE-2020-5849HIGHUnraid 6.8.0 allows authentication bypass.EPSS 93.2%KEVCVE-2012-1425—The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1EPSS 93.2%CVE-2015-5371—The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecifiedEPSS 93.2%CVE-2021-20080—Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 alEPSS 93.1%CVE-2016-4437CRITICALApache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitEPSS 93.0%KEVCVE-2021-40870CRITICALAn issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, whEPSS 93.0%KEVCVE-2005-1983—Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackEPSS 93.0%CVE-2021-38156—In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.EPSS 92.9%CVE-2018-10561CRITICALAn issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the EPSS 92.9%KEVCVE-2018-14912—cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrateEPSS 92.9%CVE-2016-4010—Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedEPSS 92.9%CVE-2021-37539—Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.EPSS 92.9%CVE-2016-7547—A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cEPSS 92.7%CVE-2019-8943—WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output imaEPSS 92.6%CVE-2007-0071—Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code viEPSS 92.5%CVE-2018-16509—An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess EPSS 92.5%