Vulnerabilidades em N/A

159.958 resultados
CVE-2012-1425The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1EPSS 93.2%CVE-2015-5371The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecifiedEPSS 93.2%CVE-2021-20080Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 alEPSS 93.1%CVE-2022-29535Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.EPSS 93.1%CVE-2016-4437CRITICALApache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitEPSS 93.0%KEVCVE-2021-40870CRITICALAn issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, whEPSS 93.0%KEVCVE-2005-1983Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackEPSS 93.0%CVE-2015-1641HIGHMicrosoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, EPSS 92.9%KEVCVE-2018-14912cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrateEPSS 92.9%CVE-2016-4010Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedEPSS 92.9%CVE-2021-37539Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.EPSS 92.9%CVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackerEPSS 92.9%CVE-2016-7547A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cEPSS 92.7%CVE-2019-8943WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output imaEPSS 92.6%CVE-2007-0071Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code viEPSS 92.5%CVE-2018-16509An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess EPSS 92.5%CVE-2012-1429The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.EPSS 92.5%CVE-2022-40022CRITICALMicrochip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.EPSS 92.5%CVE-2023-23488CRITICALThe Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' paraEPSS 92.5%CVE-2021-25282An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversEPSS 92.4%