Vulnerabilidades en n/a
160.832 resultadosCVE-2014-4872—BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute EPSS 79.3%CVE-2021-33618—Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY elEPSS 79.3%CVE-2023-20889HIGHAria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria OperatioEPSS 79.3%CVE-2021-37350—Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.EPSS 79.3%CVE-2022-37024—Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 tEPSS 79.1%CVE-2005-1921—Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1EPSS 79.1%CVE-2014-9295—Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, relEPSS 79.1%CVE-2021-33256—A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unautEPSS 79.0%CVE-2009-3548—The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default passwEPSS 79.0%CVE-2018-17553—An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 alloEPSS 79.0%CVE-2020-13947—An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp EPSS 79.0%CVE-2009-3843—HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackersEPSS 79.0%CVE-2015-7709—The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authenticationEPSS 79.0%CVE-2014-6034—Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpMEPSS 79.0%CVE-2006-4691—Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XEPSS 78.9%CVE-2013-3346HIGHAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a EPSS 78.9%KEVCVE-2013-0074HIGHMicrosoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, whichEPSS 78.9%KEVCVE-2017-17692—Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaEPSS 78.8%CVE-2012-4792HIGHUse-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web EPSS 78.8%KEVCVE-2018-7890—A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible teEPSS 78.8%