Show filters
993 Total Results
Displaying 101-110 of 993
Sort by:
Attacker Value
Moderate

CVE-2013-2492

Disclosure Date: March 15, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
0
Attacker Value
Moderate

CVE-2021-38648

Disclosure Date: September 15, 2021 (last updated November 28, 2024)
Open Management Infrastructure Elevation of Privilege Vulnerability
1
Attacker Value
High

CVE-2024-28397

Disclosure Date: June 20, 2024 (last updated June 21, 2024)
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.
1
Attacker Value
Moderate

CVE-2024-39205

Disclosure Date: October 28, 2024 (last updated October 29, 2024)
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
1
Attacker Value
Low

CVE-2020-14942

Disclosure Date: June 21, 2020 (last updated November 28, 2024)
Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py.
Attacker Value
Moderate

Nuuo Central Management Server Authenticated Arbitrary File Upload

Disclosure Date: November 27, 2018 (last updated February 13, 2020)
Nuuo Central Management Server v3.3 and prior allow authenticated users to upload files and specify the destination in a FileName header that is vulnerable to directory traversal.
0
Attacker Value
High

CVE-2020-7357

Disclosure Date: April 06, 2020 (last updated October 07, 2023)
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Attacker Value
Moderate

CVE-2024-43044

Disclosure Date: August 07, 2024 (last updated August 17, 2024)
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
Attacker Value
Very Low

CVE-2024-11477

Disclosure Date: November 22, 2024 (last updated December 21, 2024)
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.
Attacker Value
Very High

CVE-2022-3405

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.