imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2022-24697
Critica 9.8

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any op…

apache kylin
0.85EPSS
CVE-2002-0649
Alta 7.5

Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that …

microsoft data_engine · microsoft sql_server
0.85EPSS
CVE-2015-6132
Alta 7.2

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privilege…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 5
0.85EPSS
CVE-2021-38294
Critica 9.8

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentic…

apache storm
0.84EPSS
CVE-2018-1000006
Alta 8.8

GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrar…

atom electron
0.84EPSS
CVE-2015-1830
Media 5.0

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

apache activemq
0.84EPSS
CVE-2023-29325
Alta 8.1

Windows OLE Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 8
0.84EPSS
CVE-2013-7285
Critica 9.8

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. …

apache activemq · oracle endeca_information_discovery_studio · xstream xstream
0.84EPSS
CVE-2014-0556
Alta 10.0

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before …

adobe adobe_air · adobe adobe_air_sdk · adobe flash_player
0.84EPSS
CVE-2012-0779
Alta 9.3

Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to …

adobe flash_player
0.84EPSS
CVE-2024-30044
Alta 7.2

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_server
0.84EPSS
CVE-2023-50386
Alta 8.8

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0…

apache solr
0.84EPSS
CVE-2019-1620
Critica 9.8

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affe…

cisco data_center_network_manager
0.84EPSS
CVE-2023-25690
Critica 9.8

Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pa…

apache http_server
0.84EPSS
CVE-2023-39265
Bassa 3.8

Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Add…

apache superset
0.84EPSS
CVE-2005-1790
Bassa 2.6

Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched …

microsoft internet_explorer
0.83EPSS
CVE-2019-9512
Alta 7.5

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is que…

apache traffic_server · apple swiftnio · debian debian_linux · nodejs node.js
0.83EPSS
CVE-2019-1935
Critica 9.8

A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account…

cisco integrated_management_controller_supervisor · cisco ucs_director · cisco ucs_director_express_for_big_data
0.83EPSS
CVE-2009-3733
Media 5.0

Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.

vmware esx · vmware esxi · vmware server
0.83EPSS
CVE-2016-0041
Alta 7.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain priv…

microsoft internet_explorer · microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · e altri 4
0.83EPSS
CVE-2021-28482
Alta 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.83EPSS
CVE-2014-0050
Alta 7.5

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a …

apache commons_fileupload · apache tomcat · oracle retail_applications
0.83EPSS
CVE-2013-3861
Alta 7.8

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerability."

microsoft .net_framework
0.83EPSS
CVE-2024-49113
Alta 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.83EPSS
CVE-2019-0539
Alta 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.83EPSS