Vulnerabilidades en n/a

161.012 resultados
CVE-2022-31362—Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only afEPSS 18.3%CVE-2020-25042—An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager)EPSS 18.2%CVE-2015-6107—The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows EPSS 18.2%CVE-2006-0376—The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user wEPSS 18.2%CVE-2006-3660—Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: duEPSS 18.2%CVE-2021-22874—Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.EPSS 18.2%CVE-2021-22875—Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.EPSS 18.2%CVE-2009-1379—Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackeEPSS 18.2%CVE-2010-2563—The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse maEPSS 18.2%CVE-2015-2505—Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive staEPSS 18.2%CVE-2001-0609—Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed idEPSS 18.2%CVE-2022-47083—A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitraryEPSS 18.2%CVE-2002-0052—Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to readEPSS 18.2%CVE-2014-1811—The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows SeEPSS 18.2%CVE-2007-1763—The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) vEPSS 18.2%CVE-2003-1118—Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execEPSS 18.2%CVE-2017-2984—Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the h264 decoder routine. Successful eEPSS 18.2%CVE-2018-0147CRITICALA vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unautheEPSS 18.2%KEVCVE-1999-0385—The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commandEPSS 18.2%CVE-2018-15142—Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patienEPSS 18.2%