🟡 Medium — Podatności CVE o średnim poziomie ważności (CVSS 4.0–6.9). Zaplanuj remediation. Znaleziono 200 CVE.

Inne poziomy: 🔴 Critical 🟠 High ⚪ Low
CVE-2009-3960 🔴 Łataj teraz KEV

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows…

6.5 CVSS
90.4% EPSS
adobeexploit 2010-02-15
CVE-2013-0431 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified ve…

5.3 CVSS
91.6% EPSS
oracle 2013-01-31
CVE-2010-0738 🔴 Łataj teraz KEV
os

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho…

5.3 CVSS
91.3% EPSS
redhatexploit 2010-04-28
CVE-2013-7331 🔴 Łataj teraz KEV
appscloud

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by exami…

6.5 CVSS
81.8% EPSS
microsoftexploit 2014-02-26
CVE-2016-3718 🔴 Łataj teraz KEV
os

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

5.5 CVSS
83.8% EPSS
redhatssrf 2016-05-05
CVE-2016-4655 🔴 Łataj teraz KEV
os

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

5.5 CVSS
81.7% EPSS
appleexploit 2016-08-25
CVE-2013-3896 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, a…

5.5 CVSS
81.6% EPSS
microsoft 2013-10-09
CVE-2013-3900 🔴 Łataj teraz KEV
appscloud

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in a…

5.5 CVSS
78.1% EPSS
microsoftrce 2013-12-11
CVE-2017-0059 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability…

4.3 CVSS
83.9% EPSS
microsoftexploit 2017-03-17
CVE-2016-3715 🔴 Łataj teraz KEV
os

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

5.5 CVSS
77.7% EPSS
redhatexploit 2016-05-05
CVE-2014-2120 🔴 Łataj teraz KEV
network

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug I…

6.1 CVSS
69.8% EPSS
ciscoxss 2014-03-19
CVE-2016-2388 🔴 Łataj teraz KEV

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

5.3 CVSS
67.8% EPSS
sapexploit 2016-02-16
CVE-2016-9563 🔴 Łataj teraz KEV

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

6.5 CVSS
58.8% EPSS
sapxxe 2016-11-23
CVE-2025-24200 🔴 Łataj teraz KEV
os

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may…

6.1 CVSS
47.9% EPSS
apple 2025-02-10
CVE-2017-0022 🔴 Łataj teraz KEV
appscloud

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vi…

6.5 CVSS
44.1% EPSS
microsoftexploit 2017-03-17
CVE-2014-0196 🔴 Łataj teraz KEV
network

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory co…

5.5 CVSS
48.6% EPSS
f5dosexploit 2014-05-07
CVE-2016-3351 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

6.5 CVSS
40.3% EPSS
microsoftexploit 2016-09-14
CVE-2015-0071 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

6.5 CVSS
37.0% EPSS
microsoft 2015-02-11
CVE-2016-0162 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

4.3 CVSS
43.7% EPSS
microsoft 2016-04-12
CVE-2015-1769 🔴 Łataj teraz KEV
appscloud

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which…

6.6 CVSS
31.8% EPSS
CVE-2013-5223 🔴 Łataj teraz KEV
network

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username …

5.4 CVSS
35.5% EPSS
dlinkexploitxss 2013-11-19
CVE-2016-3298 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via…

6.5 CVSS
27.7% EPSS
microsoft 2016-10-14
CVE-2013-3993 🔴 Łataj teraz KEV

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

6.5 CVSS
25.5% EPSS
ibm 2014-07-07
CVE-2025-48700 🔴 Łataj teraz KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user…

6.1 CVSS
22.4% EPSS
synacorxss 2025-06-23
CVE-2012-0767 🔴 Łataj teraz KEV

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on A…

6.1 CVSS
14.9% EPSS
adobexss 2012-02-16
CVE-2026-21525 🔴 Łataj teraz KEV
appscloud

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

6.2 CVSS
12.2% EPSS
microsoft 2026-02-10
CVE-2025-47813 🔴 Łataj teraz KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

4.3 CVSS
21.3% EPSS
wftpserverexploit 2025-07-10
CVE-2011-4723 🔴 Łataj teraz KEV
network

The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.

5.7 CVSS
14.1% EPSS
dlink 2011-12-20
CVE-2012-0518 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different…

4.7 CVSS
14.5% EPSS
oracle 2012-10-16
CVE-2013-1675 🔴 Łataj teraz KEV
os

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDO…

6.5 CVSS
4.7% EPSS
redhatexploit 2013-05-16
CVE-2017-6663 🔴 Łataj teraz KEV
network

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in…

6.5 CVSS
2.3% EPSS
ciscodos 2017-08-07
CVE-2015-4902 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

5.3 CVSS
7.7% EPSS
redhat 2015-10-22
CVE-2026-20133 🔴 Łataj teraz KEV
network

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions…

6.5 CVSS
1.4% EPSS
cisco 2026-02-25
CVE-2017-12238 🔴 Łataj teraz KEV
network

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P…

6.5 CVSS
1.0% EPSS
ciscodos 2017-09-29
CVE-2017-12232 🔴 Łataj teraz KEV
network

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an aff…

6.5 CVSS
1.0% EPSS
ciscodos 2017-09-29
CVE-2024-44309 🔴 Łataj teraz KEV
os

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing m…

6.3 CVSS
1.3% EPSS
applexss 2024-11-20
CVE-2004-1464 🔴 Łataj teraz KEV
network

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

5.9 CVSS
2.1% EPSS
ciscodos 2004-12-31
CVE-2009-2055 🔴 Łataj teraz KEV
network

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

5.9 CVSS
0.4% EPSS
ciscodos 2009-08-19
CVE-2026-20122 🔴 Łataj teraz KEV
network

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid…

5.4 CVSS
1.1% EPSS
cisco 2026-02-25
CVE-2025-43520 🔴 Łataj teraz KEV
os

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1…

5.5 CVSS
0.2% EPSS
apple 2025-12-12
CVE-2025-43200 🔴 Łataj teraz KEV
os

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, …

4.2 CVSS
0.5% EPSS
apple 2025-06-16
CVE-2020-36728 ⚪ Do wiadomości

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to …

6.5 CVSS
84.4% EPSS
CVE-2024-3721 ⚪ Do wiadomości

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation o…

6.3 CVSS
83.9% EPSS
rce 2024-04-13
CVE-2022-45354 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

5.3 CVSS
87.6% EPSS
wpchill 2024-01-08
CVE-1999-0070 ⚪ Do wiadomości
apps

test-cgi program allows an attacker to list files on the server.

5.0 CVSS
85.2% EPSS
apache 1996-04-01
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2006-4704 ⚪ Do wiadomości
appscloud

Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restricti…

6.8 CVSS
72.1% EPSS
microsoftexploit 2006-11-01
CVE-1999-0016 ⚪ Do wiadomości

Land IP denial of service.

5.0 CVSS
81.0% EPSS
hpdos 1997-12-01
CVE-1999-0736 ⚪ Do wiadomości
appscloud

The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

5.0 CVSS
76.5% EPSS
microsoft 1999-05-07
CVE-1999-0278 ⚪ Do wiadomości
appscloud

In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

5.0 CVSS
76.4% EPSS
microsoft 1998-06-01
CVE-2022-45835 ⚪ Do wiadomości

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

5.8 CVSS
71.1% EPSS
phonepessrf 2023-11-13
CVE-1999-1375 ⚪ Do wiadomości
appscloud

FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

5.0 CVSS
74.0% EPSS
microsoftexploit 1999-02-11
CVE-1999-0191 ⚪ Do wiadomości
appscloud

IIS newdsn.exe CGI script allows remote users to overwrite files.

6.4 CVSS
62.0% EPSS
microsoft 1997-09-01
CVE-2006-5198 ⚪ Do wiadomości

The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."

4.0 CVSS
73.4% EPSS
winzip 2006-11-14
CVE-2006-4692 ⚪ Do wiadomości
appscloud

Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a…

5.1 CVSS
66.6% EPSS
microsoft 2006-10-10
CVE-2006-4689 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) vi…

5.0 CVSS
65.3% EPSS
microsoftdos 2006-11-14
CVE-2006-5296 ⚪ Do wiadomości
appscloud

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and appl…

4.3 CVSS
67.8% EPSS
CVE-2006-4687 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rend…

5.1 CVSS
61.9% EPSS
microsoft 2006-11-14
CVE-1999-0448 ⚪ Do wiadomości
appscloud

IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

5.0 CVSS
61.9% EPSS
microsoft 1999-01-01
CVE-2006-5544 ⚪ Do wiadomości
appscloud

Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which caus…

6.4 CVSS
54.4% EPSS
microsoftexploit 2006-10-26
CVE-1999-0386 ⚪ Do wiadomości
appscloud

Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.

5.0 CVSS
61.2% EPSS
microsoft 1999-03-01
CVE-2024-3274 ⚪ Do wiadomości

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the fi…

5.3 CVSS
57.9% EPSS
2024-04-04
CVE-2010-0010 ⚪ Do wiadomości
apps

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or…

6.8 CVSS
47.4% EPSS
CVE-2006-3868 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.

5.1 CVSS
54.5% EPSS
microsoft 2006-10-10
CVE-2006-5702 ⚪ Do wiadomości

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-…

5.0 CVSS
53.4% EPSS
tikiexploit 2006-11-04
CVE-1999-0737 ⚪ Do wiadomości
appscloud

The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

5.0 CVSS
52.9% EPSS
microsoft 1999-05-07
CVE-2023-1080 ⚪ Do wiadomości

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes…

6.1 CVSS
44.7% EPSS
gnpublisherxss 2023-02-28
CVE-2010-0639 ⚪ Do wiadomości

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer derefere…

5.0 CVSS
49.4% EPSS
squid-cachedos 2010-02-15
CVE-2024-47308 ⚪ Do wiadomości

Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.

6.5 CVSS
40.9% EPSS
templately 2024-11-01
CVE-2023-40600 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.

5.3 CVSS
46.6% EPSS
ewww 2023-11-30
CVE-2010-0494 ⚪ Do wiadomości
appscloud

Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume…

4.3 CVSS
50.2% EPSS
microsoftxss 2010-03-31
CVE-2010-0035 ⚪ Do wiadomości
appscloud

The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated …

6.3 CVSS
40.1% EPSS
microsoftdos 2010-02-10
CVE-1999-0738 ⚪ Do wiadomości
appscloud

The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

5.0 CVSS
46.4% EPSS
microsoft 1999-05-07
CVE-2010-0255 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files…

4.3 CVSS
49.3% EPSS
microsoftexploit 2010-02-04
CVE-2023-0942 ⚪ Do wiadomości

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escapin…

6.1 CVSS
40.0% EPSS
artisanworkshopxss 2023-02-21
CVE-2010-0187 ⚪ Do wiadomości

Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.

4.3 CVSS
48.9% EPSS
adobedosexploit 2010-02-15
CVE-2006-3436 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack proper…

4.3 CVSS
48.6% EPSS
microsoftxss 2006-10-10
CVE-1999-1551 ⚪ Do wiadomości

Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.

5.0 CVSS
44.7% EPSS
CVE-1999-0103 ⚪ Do wiadomości

Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.

5.0 CVSS
43.7% EPSS
1996-02-08
CVE-2022-1476 ⚪ Do wiadomości

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, a…

6.6 CVSS
35.3% EPSS
CVE-1999-0209 ⚪ Do wiadomości

The SunView (SunTools) selection_svc facility allows remote users to read files.

5.0 CVSS
42.4% EPSS
sun 1990-08-14
CVE-2024-2387 ⚪ Do wiadomości

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, an…

6.1 CVSS
36.6% EPSS
sql-injection 2024-03-20
CVE-2006-4154 ⚪ Do wiadomości
apps

Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (…

6.8 CVSS
32.8% EPSS
apache 2006-10-16
CVE-2006-2387 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a craf…

5.1 CVSS
41.2% EPSS
microsoft 2006-10-10
CVE-2006-5646 ⚪ Do wiadomości

Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigge…

5.0 CVSS
41.1% EPSS
CVE-2006-3867 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnera…

5.1 CVSS
38.9% EPSS
microsoft 2006-10-10
CVE-2006-3875 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a diff…

5.1 CVSS
38.9% EPSS
microsoft 2006-10-10
CVE-2010-1042 ⚪ Do wiadomości
appscloud

Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file…

4.3 CVSS
41.6% EPSS
microsoftdosexploit 2010-03-23
CVE-2006-5028 ⚪ Do wiadomości

Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file …

5.0 CVSS
36.5% EPSS
CVE-2006-5152 ⚪ Do wiadomości
appscloud

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an…

6.8 CVSS
27.2% EPSS
microsoftxss 2006-10-05
CVE-1999-0107 ⚪ Do wiadomości
apps

Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.

5.0 CVSS
35.6% EPSS
CVE-2010-0625 ⚪ Do wiadomości

Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary…

6.5 CVSS
27.6% EPSS
CVE-2024-51665 ⚪ Do wiadomości

Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through…

4.9 CVSS
35.4% EPSS
wpthemespacessrf 2024-11-04
CVE-1999-0508 ⚪ Do wiadomości

An account on a router, firewall, or other network device has a default, null, blank, or missing password.

4.6 CVSS
35.8% EPSS
1998-06-01
CVE-2010-1029 ⚪ Do wiadomości
os

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to…

5.0 CVSS
32.2% EPSS
appledosexploit 2010-03-19
CVE-2010-0001 ⚪ Do wiadomości

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly ex…

6.8 CVSS
22.6% EPSS
gnudos 2010-01-29
CVE-2006-5864 ⚪ Do wiadomości

Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers tha…

5.1 CVSS
30.7% EPSS
CVE-2010-0408 ⚪ Do wiadomości
apps

The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote…

5.0 CVSS
30.7% EPSS
apachedos 2010-03-05
CVE-2006-5202 ⚪ Do wiadomości

Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using …

5.0 CVSS
30.7% EPSS
linksysexploit 2006-10-10
CVE-1999-1581 ⚪ Do wiadomości
appscloud

Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP pack…

5.0 CVSS
29.4% EPSS
microsoftdos 1997-12-23
CVE-2000-0153 ⚪ Do wiadomości
appscloud

FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.

5.0 CVSS
28.7% EPSS
microsoft 1999-03-26
CVE-2006-5811 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[srcdir] parameter.

6.8 CVSS
18.6% EPSS
openemrexploit 2006-11-08
CVE-2025-1015 ⚪ Do wiadomości

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of …

5.4 CVSS
25.2% EPSS
mozilla 2025-02-04
CVE-2010-0440 ⚪ Do wiadomości
network

Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers…

4.3 CVSS
30.6% EPSS
ciscoexploitxss 2010-02-03
CVE-1999-0288 ⚪ Do wiadomości
appscloud

The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of …

5.0 CVSS
26.6% EPSS
microsoftdos 1998-08-01
CVE-2006-5295 ⚪ Do wiadomości

Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory …

5.0 CVSS
26.6% EPSS
clam_anti-virusdos 2006-10-16
CVE-2010-1127 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and appli…

5.0 CVSS
26.6% EPSS
microsoftdosexploit 2010-03-26
CVE-2006-4811 ⚪ Do wiadomości

Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) …

6.8 CVSS
17.4% EPSS
qtdos 2006-10-18
CVE-2010-0462 ⚪ Do wiadomości

Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with t…

6.5 CVSS
18.4% EPSS
CVE-1999-0513 ⚪ Do wiadomości
os

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

5.0 CVSS
25.6% EPSS
freebsddos 1998-01-05
CVE-2006-5767 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the d_root parameter.

6.8 CVSS
16.5% EPSS
drake_teamexploit 2006-11-06
CVE-2006-5846 ⚪ Do wiadomości

Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.

6.4 CVSS
18.3% EPSS
CVE-2006-5125 ⚪ Do wiadomości

Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which tri…

5.0 CVSS
25.0% EPSS
CVE-2006-5114 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command paramet…

6.8 CVSS
15.8% EPSS
sapexploitxss 2006-10-03
CVE-2006-5647 ⚪ Do wiadomości

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbi…

6.4 CVSS
17.6% EPSS
sophosdos 2006-11-01
CVE-1999-1097 ⚪ Do wiadomości
appscloud

Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.

6.4 CVSS
17.5% EPSS
microsoft 1999-05-04
CVE-2023-1263 ⚪ Do wiadomości

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to …

5.3 CVSS
22.9% EPSS
niteothemes 2023-03-07
CVE-2006-5048 ⚪ Do wiadomości

Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path…

6.8 CVSS
14.1% EPSS
waltercedricexploit 2006-09-27
CVE-2010-0488 ⚪ Do wiadomości
appscloud

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted…

6.5 CVSS
15.6% EPSS
microsoft 2010-03-31
CVE-2006-5244 ⚪ Do wiadomości

Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in…

5.1 CVSS
22.4% EPSS
opendockexploit 2006-10-12
CVE-2023-5070 ⚪ Do wiadomości

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscri…

6.5 CVSS
14.9% EPSS
ultimatelysocial 2023-10-20
CVE-2020-36723 ⚪ Do wiadomości

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthentica…

5.3 CVSS
20.7% EPSS
cridioexploit 2023-06-07
CVE-2006-5043 ⚪ Do wiadomości
apps

Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) …

6.8 CVSS
13.1% EPSS
joomla 2006-09-27
CVE-2006-5464 ⚪ Do wiadomości

Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecif…

5.0 CVSS
22.1% EPSS
mozillados 2006-11-08
CVE-2006-5661 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

6.8 CVSS
13.1% EPSS
virtechexploitxss 2006-11-03
CVE-2006-5634 ⚪ Do wiadomości

Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in user…

6.8 CVSS
12.9% EPSS
phpprofilesexploit 2006-11-01
CVE-2006-5403 ⚪ Do wiadomości

Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cau…

5.1 CVSS
21.4% EPSS
CVE-2022-1707 ⚪ Do wiadomości

The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization …

6.1 CVSS
16.2% EPSS
gtm4wpxss 2022-06-13
CVE-2006-5826 ⚪ Do wiadomości

Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/"…

5.8 CVSS
17.4% EPSS
CVE-2023-0968 ⚪ Do wiadomości

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and…

6.1 CVSS
15.8% EPSS
kibokolabsxss 2023-03-03
CVE-2006-5727 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _saz[settings][shippingfolder] and (2) _saz[settings][taxfolder] paramet…

5.1 CVSS
20.8% EPSS
sazcartexploit 2006-11-06
CVE-2010-0553 ⚪ Do wiadomości

Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence.

6.5 CVSS
13.5% EPSS
geoppdosexploit 2010-02-04
CVE-2006-5673 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

6.8 CVSS
12.0% EPSS
minibbexploit 2006-11-03
CVE-2006-5510 ⚪ Do wiadomości

Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." sequences in the Language cookie, as demonstrated by uploading a .gif fil…

6.4 CVSS
13.6% EPSS
CVE-2006-5988 ⚪ Do wiadomości
appscloud

Unspecified vulnerability in Windows 2000 Advanced Server SP4 running Active Directory allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain VulnDisco Pack module. NOTE: …

5.0 CVSS
20.5% EPSS
microsoftdos 2006-11-20
CVE-1999-0678 ⚪ Do wiadomości
apps

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

5.0 CVSS
20.4% EPSS
apache 1999-01-17
CVE-2006-5162 ⚪ Do wiadomości
appscloud

wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.

5.0 CVSS
20.2% EPSS
CVE-2006-6010 ⚪ Do wiadomości

SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnerability than CVE-2003-0747.

5.0 CVSS
20.2% EPSS
sap 2006-11-21
CVE-2010-0682 ⚪ Do wiadomości
apps

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

4.0 CVSS
25.0% EPSS
wordpress 2010-02-23
CVE-2006-5462 ⚪ Do wiadomości

Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly ha…

6.4 CVSS
12.8% EPSS
mozilla 2006-11-08
CVE-2006-5157 ⚪ Do wiadomości

Format string vulnerability in the ActiveX control (ATXCONSOLE.OCX) in TrendMicro OfficeScan Corporate Edition (OSCE) before 7.3 Patch 1 allows remote attackers to execute arbitrary code via format string identifiers in …

5.1 CVSS
19.0% EPSS
trend_micro 2006-10-05
CVE-2006-5944 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.

6.8 CVSS
10.4% EPSS
CVE-2006-5866 ⚪ Do wiadomości

Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary files via ".." sequences in the file parameter.

6.4 CVSS
12.4% EPSS
CVE-2022-2461 ⚪ Do wiadomości

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking …

5.3 CVSS
17.8% EPSS
transposhexploit 2022-09-06
CVE-2009-2693 ⚪ Do wiadomości
apps

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrate…

5.8 CVSS
15.3% EPSS
CVE-1999-1447 ⚪ Do wiadomości
appscloud

Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.

5.0 CVSS
19.3% EPSS
microsoftdos 1998-07-28
CVE-1999-0969 ⚪ Do wiadomości
appscloud

The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka S…

5.0 CVSS
19.3% EPSS
microsoftdos 1998-09-29
CVE-2006-5975 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.

6.8 CVSS
10.1% EPSS
drumsterexploitxss 2006-11-20
CVE-1999-1201 ⚪ Do wiadomości
appscloud

Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) pac…

5.0 CVSS
19.1% EPSS
microsoftdos 1999-02-06
CVE-1999-0153 ⚪ Do wiadomości
appscloud

Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.

5.0 CVSS
18.9% EPSS
microsoftdos 1997-07-01
CVE-2006-5894 ⚪ Do wiadomości

Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as…

6.8 CVSS
9.8% EPSS
CVE-2010-0166 ⚪ Do wiadomości
os

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions,…

5.1 CVSS
17.9% EPSS
appledos 2010-03-25
CVE-2010-0520 ⚪ Do wiadomości
os

Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file,…

6.8 CVSS
9.2% EPSS
CVE-2006-5310 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote at…

6.8 CVSS
8.9% EPSS
j-pierre_dezelus 2006-10-17
CVE-2021-29449 ⚪ Do wiadomości

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security…

6.3 CVSS
11.4% EPSS
CVE-2010-0718 ⚪ Do wiadomości
appscloud

Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.

4.3 CVSS
21.2% EPSS
CVE-2006-5240 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in engine/require.php in Docmint 2.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the MY_ENV[BASE_ENGINE_LOC] p…

5.1 CVSS
17.1% EPSS
docmintexploit 2006-10-12
CVE-2006-5330 ⚪ Do wiadomości

CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify …

5.0 CVSS
17.4% EPSS
adobe 2006-10-17
CVE-2006-5763 ⚪ Do wiadomości

Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP para…

5.1 CVSS
16.7% EPSS
free_php_scripts 2006-11-06
CVE-2024-43283 ⚪ Do wiadomości

Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.

5.3 CVSS
15.6% EPSS
contest-gallery 2024-08-26
CVE-2006-5636 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter.

5.1 CVSS
16.5% EPSS
swsexploit 2006-11-01
CVE-2006-5207 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the smileys_dir parameter…

5.1 CVSS
16.4% EPSS
phpmyteamexploit 2006-10-10
CVE-2024-28734 ⚪ Do wiadomości

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

6.1 CVSS
11.3% EPSS
xss 2024-03-19
CVE-2006-5524 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.

6.8 CVSS
7.7% EPSS
phplistexploitxss 2006-10-26
CVE-2023-6449 ⚪ Do wiadomości

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' functi…

6.6 CVSS
8.7% EPSS
rocklobsterlfirce 2023-12-01
CVE-2015-0797 ⚪ Do wiadomości
os

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application c…

6.8 CVSS
7.6% EPSS
redhatdos 2015-05-14
CVE-2009-2624 ⚪ Do wiadomości

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibl…

6.8 CVSS
7.3% EPSS
gnudos 2010-01-29
CVE-1999-0225 ⚪ Do wiadomości
appscloud

Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.

5.0 CVSS
16.1% EPSS
microsoftdos 1998-02-14
CVE-2006-5319 ⚪ Do wiadomości

Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter.

5.0 CVSS
16.1% EPSS
CVE-2006-5633 ⚪ Do wiadomości

Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then call…

5.0 CVSS
16.1% EPSS
mozilladosexploit 2006-10-31
CVE-2006-4819 ⚪ Do wiadomości

Heap-based buffer overflow in Opera 9.0 and 9.01 allows remote attackers to execute arbitrary code via a long URL in a tag (long link address).

5.1 CVSS
15.6% EPSS
CVE-2010-0696 ⚪ Do wiadomości

Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot)…

5.0 CVSS
16.0% EPSS
CVE-2010-0021 ⚪ Do wiadomości
appscloud

Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of ser…

5.9 CVSS
11.4% EPSS
microsoftdos 2010-02-10
CVE-1999-0128 ⚪ Do wiadomości

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

5.0 CVSS
15.8% EPSS
ibmdos 1996-12-18
CVE-2006-5164 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters.

6.8 CVSS
6.5% EPSS
CVE-2006-5915 ⚪ Do wiadomości

Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type…

6.8 CVSS
6.5% EPSS
samediaexploitxss 2006-11-15
CVE-2010-0740 ⚪ Do wiadomości
apps

The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereferen…

5.0 CVSS
15.5% EPSS
openssldos 2010-03-26
CVE-2006-5853 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy CMS (Immediacy .NET CMS) 5.2 allows remote attackers to inject arbitrary web script or HTML via the lang parameter, which is returned to the client in a…

6.8 CVSS
6.4% EPSS
immediacyexploitxss 2006-11-10
CVE-2006-4391 ⚪ Do wiadomości
os

Buffer overflow in Apple ImageIO on Apple Mac OS X 10.4 through 10.4.7 allows remote attackers to execute arbitrary code via a malformed JPEG2000 image.

5.1 CVSS
14.8% EPSS
CVE-2010-0442 ⚪ Do wiadomości
apps

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors invo…

6.5 CVSS
7.6% EPSS
CVE-1999-0174 ⚪ Do wiadomości

The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.

6.4 CVSS
8.1% EPSS
netscape 1997-02-01
CVE-2006-5052 ⚪ Do wiadomości

Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort."

5.0 CVSS
15.0% EPSS
openbsd 2006-09-27
CVE-2006-5320 ⚪ Do wiadomości

Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter.

5.0 CVSS
14.9% EPSS
CVE-2006-5762 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: this issue was later r…

5.1 CVSS
14.3% EPSS
CVE-1999-0416 ⚪ Do wiadomości
network

Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.

5.0 CVSS
14.8% EPSS
cisco 1999-03-11
CVE-2024-54502 ⚪ Do wiadomości
os

The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web con…

6.5 CVSS
7.3% EPSS
apple 2024-12-12
CVE-2010-0519 ⚪ Do wiadomości
os

Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Strea…

6.8 CVSS
5.8% EPSS
appledos 2010-03-30
CVE-2006-5645 ⚪ Do wiadomości

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service …

5.0 CVSS
14.8% EPSS
sophosdos 2006-11-01
CVE-2006-5519 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_abso…

6.8 CVSS
5.7% EPSS
mambweatherexploit 2006-10-26
CVE-2010-1003 ⚪ Do wiadomości

Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.

6.8 CVSS
5.6% EPSS
CVE-2010-0303 ⚪ Do wiadomości

mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash) via a ":help \t" private message to the MemoServ service.

5.0 CVSS
14.5% EPSS
dinko_korunicdos 2010-02-04
CVE-2010-0713 ⚪ Do wiadomości

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator for (1) requests that reset user password…

6.8 CVSS
5.5% EPSS
zenossexploit 2010-02-26
CVE-2023-44982 ⚪ Do wiadomości

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect Images (Manage Image Sizes, Thumbnails, R…

5.3 CVSS
12.9% EPSS
meowapps 2023-12-19
CVE-2006-6022 ⚪ Do wiadomości

Cross-site scripting (XSS) vulnerability in login_form.asp in BestWebApp Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

6.8 CVSS
5.2% EPSS
CVE-2006-5390 ⚪ Do wiadomości

PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path p…

6.8 CVSS
5.1% EPSS
phpbb 2006-10-18
CVE-2006-5412 ⚪ Do wiadomości

admin.php in PHP Outburst Easynews 4.4.1 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication, and gain the ability to execute arbitrary code, via the en_login_id parameter.

5.1 CVSS
13.6% EPSS
CVE-2010-1058 ⚪ Do wiadomości

Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot d…

6.8 CVSS
5.0% EPSS
CVE-2010-0433 ⚪ Do wiadomości
apps

The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attacke…

4.3 CVSS
17.3% EPSS
openssldos 2010-03-05
CVE-2010-0734 ⚪ Do wiadomości

content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote att…

6.8 CVSS
4.8% EPSS
curldos 2010-03-19
CVE-2022-45836 ⚪ Do wiadomości

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

6.3 CVSS
7.2% EPSS
w3edenxss 2023-04-18