Vulnerabilities in N/A
160,187 resultsCVE-2018-18852—Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING featureEPSS 63.8%CVE-2019-14287—In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, aEPSS 63.8%CVE-2014-9222—AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gaEPSS 63.7%CVE-2006-3726—Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to execute arbitrary coEPSS 63.7%CVE-2012-5201—Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) beEPSS 63.7%CVE-1999-0504—A Windows NT local user or administrator account has a default, null, blank, or missing password.EPSS 63.7%CVE-2005-3155—Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.EPSS 63.7%CVE-2011-0647—The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows reEPSS 63.7%CVE-2005-2127—Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute aEPSS 63.7%CVE-2015-4068CRITICALDirectory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denEPSS 63.6%KEVCVE-2021-22681CRITICALRockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix contEPSS 63.6%KEVCVE-2009-4444—Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine EPSS 63.6%CVE-2011-2474—Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary fiEPSS 63.6%CVE-2004-0313—Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP reEPSS 63.6%CVE-2005-1939—Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot)EPSS 63.6%CVE-2010-4142—Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (cEPSS 63.6%CVE-2013-5019—Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP rEPSS 63.6%CVE-2018-8735—Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commandsEPSS 63.6%CVE-2006-5216—Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI.EPSS 63.6%CVE-2019-6447—The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute appliEPSS 63.5%