imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2019-1181
Critical 9.8

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authenticat…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.76EPSS
CVE-2016-6433
High 8.8

The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.

cisco secure_firewall_management_center
0.76EPSS
CVE-2010-2550
High 10.0

The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 2 more
0.76EPSS
CVE-2004-0847
Critical 9.8

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vuln…

microsoft asp.net
0.76EPSS
CVE-2007-0940
High 9.3

Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CA…

microsoft biztalk_server · microsoft capicom
0.76EPSS
CVE-2010-2729
High 9.3

The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, whi…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.76EPSS
CVE-2010-1885
High 9.3

The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP o…

microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.75EPSS
CVE-2024-38077
Critical 9.8

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · and 2 more
0.75EPSS
CVE-2021-33037
Medium 5.3

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - To…

apache tomcat · apache tomee · debian debian_linux · mcafee epolicy_orchestrator · and 18 more
0.75EPSS
CVE-2022-20707
Critical 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.75EPSS
CVE-2001-0925
Medium 5.0

The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_nego…

apache http_server · debian debian_linux
0.75EPSS
CVE-2025-29891
Medium 4.8

Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 …

apache camel
0.75EPSS
CVE-2009-2629
High 7.5

Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.

debian debian_linux · f5 nginx · fedoraproject fedora
0.75EPSS
CVE-2020-3247
Critical 9.8

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.75EPSS
CVE-2014-9390
Critical 9.8

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up …

apple xcode · eclipse egit · eclipse jgit · git-scm git · and 2 more
0.75EPSS
CVE-2006-3942
High 7.8

The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.75EPSS
CVE-2006-4688
High 7.5

Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.75EPSS
CVE-2020-0609
Critical 9.8

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote C…

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019
0.75EPSS
CVE-2006-2447
Medium 5.1

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

apache spamassassin
0.75EPSS
CVE-1999-0128
Medium 5.0

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

digital osf_1 · ibm aix · ibm sng · linux linux_kernel · and 5 more
0.75EPSS
CVE-2022-30136
Critical 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019
0.75EPSS
CVE-2023-36756
High 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.75EPSS
CVE-2004-0206
High 7.5

Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application th…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_nt · and 1 more
0.75EPSS
CVE-1999-0874
High 10.0

Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.

microsoft internet_information_server · microsoft windows_2000 · microsoft windows_nt
0.75EPSS
CVE-2000-1089
High 10.0

Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.

microsoft windows_2000 · microsoft windows_nt
0.75EPSS