Vulnerabilities in N/A
160,184 resultsCVE-2007-3524—Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHPEPSS 64.2%CVE-2023-34039CRITICALAria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicioEPSS 64.2%CVE-2014-3789—GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspeciEPSS 64.2%CVE-2021-27212—In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function viEPSS 64.1%CVE-2020-36243—The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulneraEPSS 64.1%CVE-2016-1593—Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated admiEPSS 64.1%CVE-2017-11165—dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for thEPSS 64.1%CVE-2020-13934—An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 procesEPSS 64.1%CVE-2023-41109—SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.EPSS 64.1%CVE-2018-1000207—MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phptEPSS 64.1%CVE-2011-1565—Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSSEPSS 64.1%CVE-2012-0299—The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codeEPSS 64.1%CVE-2021-36450—Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.EPSS 64.0%CVE-2007-2939—Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL EPSS 64.0%CVE-2023-42326—An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php EPSS 64.0%CVE-2012-5067—Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers tEPSS 64.0%CVE-2009-3711—Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a dEPSS 63.9%CVE-2014-5350—Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files viaEPSS 63.9%CVE-2009-2936—The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before EPSS 63.8%CVE-2006-3730HIGHInteger overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and executeEPSS 63.8%