imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2020-16139
High 7.5

A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, th…

cisco unified_ip_conference_station_7937g_firmware
0.80EPSS
CVE-2026-41089
Critical 9.8

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022 · and 2 more
0.80EPSS
CVE-2008-5499
High 9.3

Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file.

adobe flash_player_for_linux
0.79EPSS
CVE-2020-13957
Critical 9.8

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The…

apache solr
0.79EPSS
CVE-2023-20889
High 7.5

Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.

vmware vrealize_network_insight
0.79EPSS
CVE-2006-5614
Low 2.6

Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereferen…

microsoft windows_nt_helper_components · microsoft windows_xp
0.79EPSS
CVE-2016-8740
High 7.5

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONT…

apache http_server
0.79EPSS
CVE-2022-23944
Critical 9.1

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

apache shenyu
0.79EPSS
CVE-2009-3548
High 7.5

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

apache tomcat
0.79EPSS
CVE-2020-13947
Medium 6.1

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

apache activemq · oracle communications_session_report_manager · oracle communications_session_route_manager
0.79EPSS
CVE-2018-10583
High 7.5

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an offi…

apache openoffice · canonical ubuntu_linux · debian debian_linux · libreoffice libreoffice · and 3 more
0.79EPSS
CVE-2018-0769
High 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti…

microsoft chakracore · microsoft edge
0.79EPSS
CVE-2006-4691
High 10.0

Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.

microsoft windows_2000 · microsoft windows_xp
0.79EPSS
CVE-2000-0246
Medium 5.0

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

microsoft commercial_internet_system · microsoft internet_information_server · microsoft internet_information_services · microsoft proxy_server · and 2 more
0.79EPSS
CVE-2019-1622
Medium 5.3

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls fo…

cisco data_center_network_manager
0.79EPSS
CVE-2025-66516
High 8.4

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers th…

apache tika
0.79EPSS
CVE-2015-0015
High 7.8

Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Netw…

microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_server_2012
0.79EPSS
CVE-2006-0027
High 7.5

Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.

microsoft exchange_server
0.79EPSS
CVE-2024-56325
Critical 9.8

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d {\"username\":\"hack2\",\"password\":\"hack\",\"compone…

apache pinot
0.79EPSS
CVE-2000-0302
Medium 5.0

Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.

microsoft index_server
0.79EPSS
CVE-2022-34721
Critical 9.8

Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · and 6 more
0.79EPSS
CVE-2017-0070
High 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.79EPSS
CVE-2025-0107
Critical 9.8

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations…

paloaltonetworks expedition
0.79EPSS
CVE-2009-0077
Medium 5.0

The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of…

microsoft forefront_threat_management_gateway · microsoft internet_security_and_acceleration_server
0.78EPSS
CVE-2023-38545
Critical 9.8

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host na…

fedoraproject fedora · haxx libcurl · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.78EPSS