Vulnerabilities in N/A
160,206 resultsCVE-2016-0151HIGHThe Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold EPSS 63.2%KEVCVE-2014-1773—Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) EPSS 63.1%CVE-2023-45878—GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authenticatiEPSS 63.1%CVE-2021-41081—Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.EPSS 63.1%CVE-2009-0563HIGHStack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open EPSS 63.1%KEVCVE-2012-1493—F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise ManageEPSS 63.1%CVE-2005-1323—Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long USER command.EPSS 63.1%CVE-2021-42627—The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which canEPSS 63.1%CVE-2018-16283—The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.EPSS 63.1%CVE-2016-6304—Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a dEPSS 63.0%CVE-2018-7187—The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only EPSS 63.0%CVE-2021-3017—The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading theEPSS 63.0%CVE-2012-0911—TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object iEPSS 63.0%CVE-2016-5427—PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to caEPSS 63.0%CVE-2016-0638—Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remoEPSS 62.9%CVE-2005-1812—Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code EPSS 62.9%CVE-2018-4939CRITICALAdobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of UntrusteEPSS 62.9%KEVCVE-2006-0021—Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet EPSS 62.9%CVE-2012-3811—Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 beforeEPSS 62.9%CVE-2007-2426—PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows rEPSS 62.9%