Vulnerabilidades en n/a
160.945 resultadosCVE-2022-37130—In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condEPSS 26.9%CVE-2000-0653—Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express winEPSS 26.9%CVE-2002-0076—Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet contaEPSS 26.9%CVE-2015-2469—Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbitrary code via a crafEPSS 26.9%CVE-2015-2470—Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer aEPSS 26.9%CVE-2017-6359—QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectorEPSS 26.9%CVE-2021-34805—An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operatinEPSS 26.8%CVE-2022-35628—A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.EPSS 26.8%CVE-2009-1538—The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and EPSS 26.8%CVE-2018-20148—In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediEPSS 26.8%CVE-2019-9827—Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitraEPSS 26.8%CVE-2004-0558—The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hangEPSS 26.8%CVE-2021-3654—A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desiEPSS 26.8%CVE-2009-0026—Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script EPSS 26.8%CVE-2020-11819—In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.EPSS 26.8%CVE-2015-2166—Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remotEPSS 26.8%CVE-2024-37085MEDIUMVMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain fuEPSS 26.8%KEVCVE-2016-7297—The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) viEPSS 26.8%CVE-2001-0148—The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a vaEPSS 26.8%CVE-2003-0507—Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) andEPSS 26.8%