Vulnerabilidades em N/A
160.538 resultadosCVE-2014-3669—Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x beforEPSS 28.9%CVE-2013-0235—The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attackEPSS 28.9%CVE-2013-3238—phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, whEPSS 28.9%CVE-2010-0034—Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoiEPSS 28.8%CVE-2014-6340—Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web sEPSS 28.8%CVE-2018-7182—The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via EPSS 28.8%CVE-2009-0592—Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local fileEPSS 28.8%CVE-2018-12840—Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounEPSS 28.8%CVE-2024-57004MEDIUMCross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an emailEPSS 28.8%CVE-2016-6897—Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress befEPSS 28.8%CVE-2018-12692—TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell meEPSS 28.8%CVE-2009-0950—Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (appliEPSS 28.8%CVE-2014-2324—Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to EPSS 28.8%CVE-2007-2699—The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security PolicieEPSS 28.8%CVE-2018-19660—An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmwEPSS 28.8%CVE-2014-6035—Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackerEPSS 28.8%CVE-2022-40843—The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the rouEPSS 28.8%CVE-2003-0990—The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters EPSS 28.8%CVE-2008-0533—Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco SecEPSS 28.8%CVE-2010-0252—The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft WindowsEPSS 28.8%