Vulnerabilidades em N/A
160.229 resultadosCVE-2011-5046—The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, WEPSS 45.3%CVE-2019-5127CRITICALA command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. ExploitableEPSS 45.3%CVE-2023-44466—An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffEPSS 45.3%CVE-2018-15535—/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be withiEPSS 45.2%CVE-2004-1812—Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 allow remote attackerEPSS 45.2%CVE-2022-21826—Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request,EPSS 45.2%CVE-2020-35313—A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remEPSS 45.2%CVE-2011-2386—VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary coEPSS 45.2%CVE-2019-12384—FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-EPSS 45.2%CVE-2014-3505—Double free vulnerability in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0EPSS 45.2%CVE-2013-0209—lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migrEPSS 45.2%CVE-2004-0595—The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restrictiEPSS 45.2%CVE-2012-5081—Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier,EPSS 45.1%CVE-2024-48760CRITICALAn issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicEPSS 45.1%CVE-2019-13344—An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to EPSS 45.1%CVE-2020-26879—Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with EPSS 45.1%CVE-2022-45938HIGHAn issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device EPSS 45.1%CVE-2021-21974HIGHOpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overfloEPSS 45.1%CVE-2019-5097MEDIUMA denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in veEPSS 45.1%CVE-2007-5009—PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows reEPSS 45.0%