🟡 Medium — Podatności CVE o średnim poziomie ważności (CVSS 4.0–6.9). Zaplanuj remediation. Znaleziono 200 CVE.

Inne poziomy: 🔴 Critical 🟠 High ⚪ Low
CVE-2009-3960 🔴 Łataj teraz KEV

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows…

6.5 CVSS
90.4% EPSS
adobeexploit 2010-02-15
CVE-2013-0431 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified ve…

5.3 CVSS
91.6% EPSS
oracle 2013-01-31
CVE-2010-0738 🔴 Łataj teraz KEV
os

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho…

5.3 CVSS
91.3% EPSS
redhatexploit 2010-04-28
CVE-2013-7331 🔴 Łataj teraz KEV
appscloud

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by exami…

6.5 CVSS
81.8% EPSS
microsoftexploit 2014-02-26
CVE-2016-3718 🔴 Łataj teraz KEV
os

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

5.5 CVSS
83.8% EPSS
redhatssrf 2016-05-05
CVE-2016-4655 🔴 Łataj teraz KEV
os

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

5.5 CVSS
81.7% EPSS
appleexploit 2016-08-25
CVE-2013-3896 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, a…

5.5 CVSS
81.6% EPSS
microsoft 2013-10-09
CVE-2013-3900 🔴 Łataj teraz KEV
appscloud

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in a…

5.5 CVSS
78.1% EPSS
microsoftrce 2013-12-11
CVE-2017-0059 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability…

4.3 CVSS
83.9% EPSS
microsoftexploit 2017-03-17
CVE-2016-3715 🔴 Łataj teraz KEV
os

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

5.5 CVSS
77.7% EPSS
redhatexploit 2016-05-05
CVE-2014-2120 🔴 Łataj teraz KEV
network

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug I…

6.1 CVSS
69.8% EPSS
ciscoxss 2014-03-19
CVE-2016-2388 🔴 Łataj teraz KEV

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

5.3 CVSS
67.8% EPSS
sapexploit 2016-02-16
CVE-2016-9563 🔴 Łataj teraz KEV

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

6.5 CVSS
58.8% EPSS
sapxxe 2016-11-23
CVE-2025-24200 🔴 Łataj teraz KEV
os

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may…

6.1 CVSS
47.9% EPSS
apple 2025-02-10
CVE-2017-0022 🔴 Łataj teraz KEV
appscloud

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vi…

6.5 CVSS
44.1% EPSS
microsoftexploit 2017-03-17
CVE-2014-0196 🔴 Łataj teraz KEV
network

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory co…

5.5 CVSS
48.6% EPSS
f5dosexploit 2014-05-07
CVE-2016-3351 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

6.5 CVSS
40.3% EPSS
microsoftexploit 2016-09-14
CVE-2015-0071 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

6.5 CVSS
37.0% EPSS
microsoft 2015-02-11
CVE-2016-0162 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

4.3 CVSS
43.7% EPSS
microsoft 2016-04-12
CVE-2015-1769 🔴 Łataj teraz KEV
appscloud

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which…

6.6 CVSS
31.8% EPSS
CVE-2013-5223 🔴 Łataj teraz KEV
network

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username …

5.4 CVSS
35.5% EPSS
dlinkexploitxss 2013-11-19
CVE-2016-3298 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via…

6.5 CVSS
27.7% EPSS
microsoft 2016-10-14
CVE-2013-3993 🔴 Łataj teraz KEV

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

6.5 CVSS
25.5% EPSS
ibm 2014-07-07
CVE-2026-7473 🔴 Łataj teraz KEV

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch w…

5.8 CVSS
27.2% EPSS
arista 2026-06-05
CVE-2025-48700 🔴 Łataj teraz KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user…

6.1 CVSS
22.4% EPSS
synacorxss 2025-06-23
CVE-2012-0767 🔴 Łataj teraz KEV

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on A…

6.1 CVSS
14.9% EPSS
adobexss 2012-02-16
CVE-2026-9082 🔴 Łataj teraz KEV

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 befor…

6.5 CVSS
12.6% EPSS
sql-injection 2026-05-20
CVE-2026-21525 🔴 Łataj teraz KEV
appscloud

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

6.2 CVSS
12.2% EPSS
microsoft 2026-02-10
CVE-2025-47813 🔴 Łataj teraz KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

4.3 CVSS
21.3% EPSS
wftpserverexploit 2025-07-10
CVE-2011-4723 🔴 Łataj teraz KEV
network

The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.

5.7 CVSS
14.1% EPSS
dlink 2011-12-20
CVE-2026-32201 🔴 Łataj teraz KEV
appscloud

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

6.5 CVSS
8.9% EPSS
microsoft 2026-04-14
CVE-2021-27562 🔴 Łataj teraz KEV

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

5.5 CVSS
10.9% EPSS
trustedfirmware 2021-05-25
CVE-2012-0518 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different…

4.7 CVSS
14.5% EPSS
oracle 2012-10-16
CVE-2013-1675 🔴 Łataj teraz KEV
os

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDO…

6.5 CVSS
4.7% EPSS
redhatexploit 2013-05-16
CVE-2017-6663 🔴 Łataj teraz KEV
network

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in…

6.5 CVSS
2.3% EPSS
ciscodos 2017-08-07
CVE-2026-20262 🔴 Łataj teraz KEV
network

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. Th…

6.5 CVSS
1.7% EPSS
cisco 2026-06-15
CVE-2015-4902 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

5.3 CVSS
7.7% EPSS
redhat 2015-10-22
CVE-2026-20133 🔴 Łataj teraz KEV
network

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions…

6.5 CVSS
1.4% EPSS
cisco 2026-02-25
CVE-2026-34926 🔴 Łataj teraz KEV

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installa…

6.7 CVSS
0.2% EPSS
path-traversal 2026-05-21
CVE-2017-12238 🔴 Łataj teraz KEV
network

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P…

6.5 CVSS
1.0% EPSS
ciscodos 2017-09-29
CVE-2017-12232 🔴 Łataj teraz KEV
network

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an aff…

6.5 CVSS
1.0% EPSS
ciscodos 2017-09-29
CVE-2024-44309 🔴 Łataj teraz KEV
os

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing m…

6.3 CVSS
1.3% EPSS
applexss 2024-11-20
CVE-2026-32202 🔴 Łataj teraz KEV
appscloud

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

4.3 CVSS
10.8% EPSS
microsoft 2026-04-14
CVE-2004-1464 🔴 Łataj teraz KEV
network

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

5.9 CVSS
2.1% EPSS
ciscodos 2004-12-31
CVE-2009-2055 🔴 Łataj teraz KEV
network

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

5.9 CVSS
0.4% EPSS
ciscodos 2009-08-19
CVE-2024-50302 🔴 Łataj teraz KEV

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during …

5.5 CVSS
1.7% EPSS
siemens 2024-11-19
CVE-2026-20122 🔴 Łataj teraz KEV
network

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid…

5.4 CVSS
1.1% EPSS
cisco 2026-02-25
CVE-2025-43520 🔴 Łataj teraz KEV
os

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1…

5.5 CVSS
0.2% EPSS
apple 2025-12-12
CVE-2026-45498 🔴 Łataj teraz KEV
appscloud

Microsoft Defender Denial of Service Vulnerability

4.0 CVSS
4.1% EPSS
microsoftdos 2026-05-20
CVE-2025-43200 🔴 Łataj teraz KEV
os

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, …

4.2 CVSS
0.5% EPSS
apple 2025-06-16
CVE-2013-2566 ⚪ Do wiadomości

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a l…

5.9 CVSS
93.2% EPSS
fujitsu 2013-03-15
CVE-2017-5753 ⚪ Do wiadomości

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

5.6 CVSS
94.3% EPSS
intelexploit 2018-01-04
CVE-2023-25136 ⚪ Do wiadomości

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the defaul…

6.5 CVSS
88.3% EPSS
netappexploitrce 2023-02-03
CVE-1999-0016 ⚪ Do wiadomości

Land IP denial of service.

5.0 CVSS
95.7% EPSS
hpdos 1997-12-01
CVE-2016-6210 ⚪ Do wiadomości

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by lever…

5.9 CVSS
90.0% EPSS
openbsd 2017-02-13
CVE-2017-5487 ⚪ Do wiadomości
apps

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain …

5.3 CVSS
92.5% EPSS
wordpress 2017-01-15
CVE-2014-0094 ⚪ Do wiadomości
apps

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

5.0 CVSS
93.1% EPSS
apache 2014-03-11
CVE-2017-5754 ⚪ Do wiadomości

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data c…

5.6 CVSS
89.3% EPSS
intel 2018-01-04
CVE-2020-36728 ⚪ Do wiadomości

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to …

6.5 CVSS
84.4% EPSS
CVE-2024-3721 ⚪ Do wiadomości

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation o…

6.3 CVSS
83.9% EPSS
rce 2024-04-13
CVE-2022-45354 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

5.3 CVSS
87.6% EPSS
wpchill 2024-01-08
CVE-2013-4467 ⚪ Do wiadomości

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the ca…

6.5 CVSS
78.3% EPSS
CVE-2025-26465 ⚪ Do wiadomości

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH …

6.8 CVSS
73.6% EPSS
openbsd 2025-02-18
CVE-2013-2641 ⚪ Do wiadomości

Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.

5.0 CVSS
82.3% EPSS
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2006-4704 ⚪ Do wiadomości
appscloud

Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restricti…

6.8 CVSS
72.1% EPSS
microsoftexploit 2006-11-01
CVE-2016-0777 ⚪ Do wiadomości

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buff…

6.5 CVSS
71.7% EPSS
openbsd 2016-01-14
CVE-2021-45105 ⚪ Do wiadomości
appsos

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t…

5.9 CVSS
74.5% EPSS
oracledos 2021-12-18
CVE-2009-2495 ⚪ Do wiadomości
appscloud

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which …

6.5 CVSS
68.4% EPSS
microsoft 2009-07-29
CVE-2022-45835 ⚪ Do wiadomości

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

5.8 CVSS
71.1% EPSS
phonepessrf 2023-11-13
CVE-2014-2424 ⚪ Do wiadomości
appsos

Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.

4.0 CVSS
80.0% EPSS
oracle 2014-04-16
CVE-1999-0128 ⚪ Do wiadomości

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

5.0 CVSS
74.1% EPSS
ibmdos 1996-12-18
CVE-2025-1035 ⚪ Do wiadomości

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects KLog Server: before …

5.7 CVSS
70.4% EPSS
path-traversal 2025-02-18
CVE-2014-2525 ⚪ Do wiadomości

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a…

6.8 CVSS
63.2% EPSS
CVE-1999-1551 ⚪ Do wiadomości

Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.

5.0 CVSS
71.8% EPSS
CVE-2014-2324 ⚪ Do wiadomości
os

Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_che…

5.0 CVSS
71.7% EPSS
CVE-1999-0513 ⚪ Do wiadomości
os

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

5.0 CVSS
70.5% EPSS
freebsddos 1998-01-05
CVE-2013-2143 ⚪ Do wiadomości
os

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account …

6.5 CVSS
61.5% EPSS
redhatexploit 2014-04-17
CVE-2006-5198 ⚪ Do wiadomości

The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."

4.0 CVSS
73.4% EPSS
winzip 2006-11-14
CVE-2006-4692 ⚪ Do wiadomości
appscloud

Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a…

5.1 CVSS
66.6% EPSS
microsoft 2006-10-10
CVE-2006-4689 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) vi…

5.0 CVSS
65.3% EPSS
microsoftdos 2006-11-14
CVE-1999-0278 ⚪ Do wiadomości
appscloud

In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

5.0 CVSS
64.8% EPSS
microsoft 1998-06-01
CVE-2013-5704 ⚪ Do wiadomości
apps

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the …

5.0 CVSS
64.7% EPSS
apacheexploit 2014-04-15
CVE-2006-5296 ⚪ Do wiadomości
appscloud

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and appl…

4.3 CVSS
67.8% EPSS
CVE-2006-4687 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rend…

5.1 CVSS
61.9% EPSS
microsoft 2006-11-14
CVE-2014-2314 ⚪ Do wiadomości
dev

Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

4.3 CVSS
65.8% EPSS
CVE-2021-44832 ⚪ Do wiadomości
appsos

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so…

6.6 CVSS
53.6% EPSS
oraclerce 2021-12-28
CVE-2006-5544 ⚪ Do wiadomości
appscloud

Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which caus…

6.4 CVSS
54.4% EPSS
microsoftexploit 2006-10-26
CVE-1999-0191 ⚪ Do wiadomości
appscloud

IIS newdsn.exe CGI script allows remote users to overwrite files.

6.4 CVSS
53.3% EPSS
microsoft 1997-09-01
CVE-2024-3274 ⚪ Do wiadomości

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the fi…

5.3 CVSS
57.9% EPSS
2024-04-04
CVE-2023-48795 ⚪ Do wiadomości
os

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti…

5.9 CVSS
53.6% EPSS
redhatexploit 2023-12-18
CVE-2016-3115 ⚪ Do wiadomości

Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_a…

6.4 CVSS
50.4% EPSS
openbsd 2016-03-22
CVE-2010-0010 ⚪ Do wiadomości
apps

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or…

6.8 CVSS
47.4% EPSS
CVE-2006-3868 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.

5.1 CVSS
54.5% EPSS
microsoft 2006-10-10
CVE-2014-0128 ⚪ Do wiadomości

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.

5.0 CVSS
55.0% EPSS
squid-cachedos 2014-04-14
CVE-2006-5702 ⚪ Do wiadomości

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-…

5.0 CVSS
53.4% EPSS
tikiexploit 2006-11-04
CVE-2014-2238 ⚪ Do wiadomości

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id…

6.5 CVSS
45.4% EPSS
CVE-2014-0098 ⚪ Do wiadomości
appsos

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted coo…

5.0 CVSS
50.8% EPSS
oracledos 2014-03-18
CVE-2013-3706 ⚪ Do wiadomości

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN…

5.0 CVSS
50.5% EPSS
CVE-2023-1080 ⚪ Do wiadomości

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes…

6.1 CVSS
44.7% EPSS
gnpublisherxss 2023-02-28
CVE-2010-0639 ⚪ Do wiadomości

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer derefere…

5.0 CVSS
49.4% EPSS
squid-cachedos 2010-02-15
CVE-2018-3639 ⚪ Do wiadomości

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta…

5.5 CVSS
46.7% EPSS
intelexploit 2018-05-22
CVE-2016-7981 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

6.1 CVSS
43.5% EPSS
spipxss 2017-01-18
CVE-2014-2668 ⚪ Do wiadomości
apps

Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

5.0 CVSS
48.8% EPSS
apachedosexploit 2014-03-28
CVE-2024-47308 ⚪ Do wiadomości

Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.

6.5 CVSS
40.9% EPSS
templately 2024-11-01
CVE-2023-40600 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.

5.3 CVSS
46.6% EPSS
ewww 2023-11-30
CVE-1999-0209 ⚪ Do wiadomości

The SunView (SunTools) selection_svc facility allows remote users to read files.

5.0 CVSS
47.8% EPSS
sun 1990-08-14
CVE-2010-0494 ⚪ Do wiadomości
appscloud

Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume…

4.3 CVSS
50.2% EPSS
microsoftxss 2010-03-31
CVE-2010-0035 ⚪ Do wiadomości
appscloud

The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated …

6.3 CVSS
40.1% EPSS
microsoftdos 2010-02-10
CVE-2010-0255 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files…

4.3 CVSS
49.3% EPSS
microsoftexploit 2010-02-04
CVE-2023-0942 ⚪ Do wiadomości

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escapin…

6.1 CVSS
40.0% EPSS
artisanworkshopxss 2023-02-21
CVE-2010-0187 ⚪ Do wiadomości

Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.

4.3 CVSS
48.9% EPSS
adobedosexploit 2010-02-15
CVE-2006-3436 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack proper…

4.3 CVSS
48.6% EPSS
microsoftxss 2006-10-10
CVE-1999-0736 ⚪ Do wiadomości
appscloud

The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

5.0 CVSS
44.9% EPSS
microsoft 1999-05-07
CVE-2022-1476 ⚪ Do wiadomości

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, a…

6.6 CVSS
35.3% EPSS
CVE-2025-26466 ⚪ Do wiadomości

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange…

5.9 CVSS
38.5% EPSS
openbsddos 2025-02-28
CVE-2024-2387 ⚪ Do wiadomości

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, an…

6.1 CVSS
36.6% EPSS
sql-injection 2024-03-20
CVE-2006-4154 ⚪ Do wiadomości
apps

Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (…

6.8 CVSS
32.8% EPSS
apache 2006-10-16
CVE-2013-5680 ⚪ Do wiadomości

Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER comman…

6.8 CVSS
32.8% EPSS
CVE-2006-2387 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a craf…

5.1 CVSS
41.2% EPSS
microsoft 2006-10-10
CVE-2006-5646 ⚪ Do wiadomości

Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigge…

5.0 CVSS
41.1% EPSS
CVE-2014-2671 ⚪ Do wiadomości
appscloud

Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted WAV file.

6.8 CVSS
30.9% EPSS
microsoftdosexploit 2014-03-31
CVE-2013-6438 ⚪ Do wiadomości
os

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a deni…

5.0 CVSS
39.6% EPSS
canonicaldos 2014-03-18
CVE-2006-3867 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnera…

5.1 CVSS
38.9% EPSS
microsoft 2006-10-10
CVE-2006-3875 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a diff…

5.1 CVSS
38.9% EPSS
microsoft 2006-10-10
CVE-2014-0166 ⚪ Do wiadomości
apps

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote atta…

6.4 CVSS
31.6% EPSS
wordpress 2014-04-10
CVE-2010-1042 ⚪ Do wiadomości
appscloud

Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file…

4.3 CVSS
41.6% EPSS
microsoftdosexploit 2010-03-23
CVE-2016-6897 ⚪ Do wiadomości
apps

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for …

6.5 CVSS
30.3% EPSS
wordpress 2017-01-18
CVE-2006-5028 ⚪ Do wiadomości

Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file …

5.0 CVSS
36.5% EPSS
CVE-2006-5152 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an…

6.8 CVSS
27.2% EPSS
microsoftxss 2006-10-05
CVE-1999-0015 ⚪ Do wiadomości

Teardrop IP denial of service.

5.0 CVSS
35.7% EPSS
hpdos 1997-12-16
CVE-2010-0625 ⚪ Do wiadomości

Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary…

6.5 CVSS
27.6% EPSS
CVE-2024-51665 ⚪ Do wiadomości

Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through…

4.9 CVSS
35.4% EPSS
wpthemespacessrf 2024-11-04
CVE-1999-0270 ⚪ Do wiadomości

Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.

5.0 CVSS
32.4% EPSS
sgipath-traversal 1998-04-03
CVE-2010-1029 ⚪ Do wiadomości
os

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to…

5.0 CVSS
32.2% EPSS
appledosexploit 2010-03-19
CVE-2014-0315 ⚪ Do wiadomości
appscloud

Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and…

6.9 CVSS
22.6% EPSS
microsoft 2014-04-08
CVE-2020-8554 ⚪ Do wiadomości
appsos

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patc…

6.3 CVSS
25.3% EPSS
oracleexploit 2021-01-21
CVE-1999-0517 ⚪ Do wiadomości

An SNMP community name is the default (e.g. public), null, or missing.

5.9 CVSS
27.2% EPSS
hp 1997-01-01
CVE-2010-0001 ⚪ Do wiadomości

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly ex…

6.8 CVSS
22.6% EPSS
gnudos 2010-01-29
CVE-2015-8139 ⚪ Do wiadomości

ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecified vectors.

5.3 CVSS
30.1% EPSS
ntp 2017-01-30
CVE-1999-0678 ⚪ Do wiadomości
apps

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

5.0 CVSS
31.4% EPSS
apache 1999-01-17
CVE-2006-5864 ⚪ Do wiadomości

Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers tha…

5.1 CVSS
30.7% EPSS
CVE-2016-5725 ⚪ Do wiadomości

Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a r…

5.9 CVSS
26.7% EPSS
CVE-1999-0077 ⚪ Do wiadomości
appscloud

Predictable TCP sequence numbers allow spoofing.

5.0 CVSS
30.9% EPSS
microsoft 1995-01-01
CVE-2010-0408 ⚪ Do wiadomości
apps

The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote…

5.0 CVSS
30.7% EPSS
apachedos 2010-03-05
CVE-2006-5202 ⚪ Do wiadomości

Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using …

5.0 CVSS
30.7% EPSS
linksysexploit 2006-10-10
CVE-1999-1375 ⚪ Do wiadomości
appscloud

FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

5.0 CVSS
30.6% EPSS
microsoftexploit 1999-02-11
CVE-2013-6474 ⚪ Do wiadomości

Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.

6.8 CVSS
20.8% EPSS
CVE-2013-6475 ⚪ Do wiadomości

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, whic…

6.8 CVSS
20.7% EPSS
CVE-1999-0070 ⚪ Do wiadomości
apps

test-cgi program allows an attacker to list files on the server.

5.0 CVSS
29.6% EPSS
apache 1996-04-01
CVE-1999-0738 ⚪ Do wiadomości
appscloud

The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

5.0 CVSS
28.9% EPSS
microsoft 1999-05-07
CVE-2015-8140 ⚪ Do wiadomości

The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sniffing the network.

4.8 CVSS
29.9% EPSS
ntp 2017-01-30
CVE-1999-0737 ⚪ Do wiadomości
appscloud

The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

5.0 CVSS
28.1% EPSS
microsoft 1999-05-07
CVE-2006-5811 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[srcdir] parameter.

6.8 CVSS
18.6% EPSS
openemrexploit 2006-11-08
CVE-2025-1015 ⚪ Do wiadomości

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of …

5.4 CVSS
25.2% EPSS
mozilla 2025-02-04
CVE-2010-0440 ⚪ Do wiadomości
network

Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers…

4.3 CVSS
30.6% EPSS
ciscoexploitxss 2010-02-03
CVE-1999-0524 ⚪ Do wiadomości
os

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

4.0 CVSS
31.6% EPSS
apple 1997-08-01
CVE-2006-5295 ⚪ Do wiadomości

Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory …

5.0 CVSS
26.6% EPSS
clam_anti-virusdos 2006-10-16
CVE-2010-1127 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and appli…

5.0 CVSS
26.6% EPSS
microsoftdosexploit 2010-03-26
CVE-2006-4811 ⚪ Do wiadomości

Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) …

6.8 CVSS
17.4% EPSS
qtdos 2006-10-18
CVE-2010-0462 ⚪ Do wiadomości

Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with t…

6.5 CVSS
18.4% EPSS
CVE-2006-5767 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the d_root parameter.

6.8 CVSS
16.5% EPSS
drake_teamexploit 2006-11-06
CVE-2006-5846 ⚪ Do wiadomości

Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.

6.4 CVSS
18.3% EPSS
CVE-2014-0983 ⚪ Do wiadomości
appsos

Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Ac…

6.9 CVSS
15.6% EPSS
oracleexploit 2014-03-31
CVE-2006-5125 ⚪ Do wiadomości

Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which tri…

5.0 CVSS
25.0% EPSS
CVE-2022-26934 ⚪ Do wiadomości
appscloud

Windows Graphics Component Information Disclosure Vulnerability

6.5 CVSS
17.4% EPSS
microsoft 2022-05-10
CVE-2006-5114 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command paramet…

6.8 CVSS
15.8% EPSS
sapexploitxss 2006-10-03
CVE-2013-0303 ⚪ Do wiadomości

Unspecified vulnerability in core/ajax/translations.php in ownCloud before 4.0.12 and 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via unknown vectors. NOTE: this entry has been SPL…

6.5 CVSS
17.3% EPSS
owncloud 2014-03-24
CVE-2023-51385 ⚪ Do wiadomości
os

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git …

6.5 CVSS
17.2% EPSS
debianrce 2023-12-18
CVE-2006-5647 ⚪ Do wiadomości

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbi…

6.4 CVSS
17.6% EPSS
sophosdos 2006-11-01
CVE-2023-1263 ⚪ Do wiadomości

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to …

5.3 CVSS
22.9% EPSS
niteothemes 2023-03-07
CVE-1999-0448 ⚪ Do wiadomości
appscloud

IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

5.0 CVSS
24.2% EPSS
microsoft 1999-01-01
CVE-2014-2270 ⚪ Do wiadomości
os

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

4.3 CVSS
27.1% EPSS
canonicaldos 2014-03-14
CVE-2015-6477 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors…

6.1 CVSS
18.0% EPSS
nordexxss 2015-10-18
CVE-2014-2399 ⚪ Do wiadomości
appsos

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly L…

4.3 CVSS
26.7% EPSS
oracle 2014-04-16
CVE-2006-5048 ⚪ Do wiadomości

Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path…

6.8 CVSS
14.1% EPSS
waltercedricexploit 2006-09-27
CVE-2010-0488 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted…

6.5 CVSS
15.6% EPSS
microsoft 2010-03-31
CVE-2006-5244 ⚪ Do wiadomości

Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in…

5.1 CVSS
22.4% EPSS
opendockexploit 2006-10-12
CVE-2013-6473 ⚪ Do wiadomości

Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.

6.8 CVSS
13.7% EPSS
CVE-2023-5070 ⚪ Do wiadomości

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscri…

6.5 CVSS
14.9% EPSS
ultimatelysocial 2023-10-20
CVE-2020-36723 ⚪ Do wiadomości

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthentica…

5.3 CVSS
20.7% EPSS
cridioexploit 2023-06-07
CVE-2006-5043 ⚪ Do wiadomości
apps

Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) …

6.8 CVSS
13.1% EPSS
joomla 2006-09-27
CVE-2006-5464 ⚪ Do wiadomości

Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecif…

5.0 CVSS
22.1% EPSS
mozillados 2006-11-08
CVE-2006-5661 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

6.8 CVSS
13.1% EPSS
virtechexploitxss 2006-11-03
CVE-2006-5634 ⚪ Do wiadomości

Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in user…

6.8 CVSS
12.9% EPSS
phpprofilesexploit 2006-11-01
CVE-2006-5403 ⚪ Do wiadomości

Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cau…

5.1 CVSS
21.4% EPSS
CVE-2022-1707 ⚪ Do wiadomości

The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization …

6.1 CVSS
16.2% EPSS
gtm4wpxss 2022-06-13
CVE-2026-2131 ⚪ Do wiadomości

A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument text leads to os command injection. Remote exploitation of th…

6.3 CVSS
15.0% EPSS
CVE-2006-5826 ⚪ Do wiadomości

Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/"…

5.8 CVSS
17.4% EPSS
CVE-2023-0968 ⚪ Do wiadomości

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and…

6.1 CVSS
15.8% EPSS
kibokolabsxss 2023-03-03
CVE-2006-5727 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _saz[settings][shippingfolder] and (2) _saz[settings][taxfolder] paramet…

5.1 CVSS
20.8% EPSS
sazcartexploit 2006-11-06
CVE-1999-0288 ⚪ Do wiadomości
appscloud

The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of …

5.0 CVSS
21.3% EPSS
microsoftdos 1998-08-01
CVE-1999-0153 ⚪ Do wiadomości
appscloud

Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.

5.0 CVSS
21.1% EPSS
microsoftdos 1997-07-01
CVE-2010-0553 ⚪ Do wiadomości

Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence.

6.5 CVSS
13.5% EPSS
geoppdosexploit 2010-02-04
CVE-2006-5673 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

6.8 CVSS
12.0% EPSS
minibbexploit 2006-11-03
CVE-2015-7977 ⚪ Do wiadomości
os

ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.

5.9 CVSS
16.4% EPSS
freebsddos 2017-01-30
CVE-1999-1387 ⚪ Do wiadomości
appscloud

Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel …

5.0 CVSS
20.8% EPSS
microsoftdos 1997-04-02
CVE-1999-1581 ⚪ Do wiadomości
appscloud

Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP pack…

5.0 CVSS
20.6% EPSS
microsoftdos 1997-12-23
CVE-2006-5510 ⚪ Do wiadomości

Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." sequences in the Language cookie, as demonstrated by uploading a .gif fil…

6.4 CVSS
13.6% EPSS
CVE-2006-5988 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Windows 2000 Advanced Server SP4 running Active Directory allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain VulnDisco Pack module. NOTE: …

5.0 CVSS
20.5% EPSS
microsoftdos 2006-11-20