Vulnerabilidades en n/a
160.843 resultadosCVE-2021-35478—Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used EPSS 76.6%CVE-2006-5745—Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 onEPSS 76.6%CVE-2022-45699CRITICALCommand injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrEPSS 76.6%CVE-2005-3081—wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command.EPSS 76.6%CVE-2020-13638—lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue hEPSS 76.6%CVE-2020-13965MEDIUMAn issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/EPSS 76.6%KEVCVE-2022-44267MEDIUMImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waEPSS 76.6%CVE-2000-0649—IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected byEPSS 76.6%CVE-2014-3936—Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-50EPSS 76.6%CVE-2018-14728—upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.EPSS 76.5%CVE-2018-12710—An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilegEPSS 76.5%CVE-2010-2156—ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length clEPSS 76.4%CVE-2011-3556—Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 EPSS 76.4%CVE-2013-0229—The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denialEPSS 76.4%CVE-2009-1979—Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affectEPSS 76.4%CVE-2020-35951CRITICALAn issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wEPSS 76.3%CVE-2010-4417—Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.EPSS 76.3%CVE-2018-15811HIGHDNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.EPSS 76.3%KEVCVE-2014-5073—vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacEPSS 76.3%CVE-2006-5779—OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, wEPSS 76.3%