Vulnerabilidades en n/a

160.832 resultados
CVE-2013-2028—The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of serviEPSS 87.5%CVE-2020-15867—The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if accEPSS 87.4%CVE-2019-9515HIGHSome HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceEPSS 87.4%CVE-2017-11610—The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated usEPSS 87.4%CVE-2018-7584—In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while paEPSS 87.3%CVE-2014-6324HIGHThe Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, WindEPSS 87.3%KEVCVE-2020-10546—rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are EPSS 87.3%CVE-2022-26143CRITICALThe TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers toEPSS 87.3%KEVCVE-2000-1209—The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) EPSS 87.3%CVE-2021-32305—WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.EPSS 87.3%CVE-2021-22881—The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `HosEPSS 87.3%CVE-2017-5487—wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not propEPSS 87.3%CVE-2012-1424—The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.EPSS 87.3%CVE-2000-0778—IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header,EPSS 87.3%CVE-2021-3122—CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document EPSS 87.3%CVE-2018-5999—An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requEPSS 87.3%CVE-2009-3555CRITICALThe TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thEPSS 87.3%CVE-2013-1488—The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execEPSS 87.2%CVE-2019-11358—jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypEPSS 87.2%CVE-2020-26948—Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.EPSS 87.2%