Vulnerabilidades en n/a

160.832 resultados
CVE-2019-13372—/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbEPSS 82.5%CVE-2017-9828—'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which alEPSS 82.5%CVE-2013-3861—Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash orEPSS 82.4%CVE-2022-28368—Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (withEPSS 82.4%CVE-2018-16042—Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earEPSS 82.4%CVE-2011-0276—HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager EPSS 82.4%CVE-2014-1510—The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 EPSS 82.3%CVE-2020-27955—Git LFS 2.12.0 allows Remote Code Execution.EPSS 82.3%CVE-2018-9995—TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR LoginEPSS 82.3%CVE-2021-26120—Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.EPSS 82.3%CVE-2019-7254—Linear eMerge E3-Series devices allow File Inclusion.EPSS 82.3%CVE-2023-20888HIGHAria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria OEPSS 82.3%CVE-2009-2521—Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticaEPSS 82.3%CVE-2011-2140—Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 oEPSS 82.3%CVE-2007-1036—The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackEPSS 82.3%CVE-2020-9465—An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowingEPSS 82.2%CVE-2003-0818—Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and lEPSS 82.2%CVE-2010-1297HIGHAdobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,EPSS 82.2%KEVCVE-2014-9016—The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal alloEPSS 82.2%CVE-2012-0053—protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (EPSS 82.2%