Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-9956 |
|
Vulnerability in schneider-electric (CVE-2017-9956)
vulnerability in schneider-electric (CVE-2017-9956). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-0238 |
|
Information Disclosure in privilege-escalation (CVE-2015-0238)
vulnerability in privilege-escalation (CVE-2015-0238). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-0997 |
|
Vulnerability in dos (CVE-2014-0997)
vulnerability in dos (CVE-2014-0997). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-8156 |
|
Vulnerability in dos (CVE-2014-8156)
vulnerability in dos (CVE-2014-8156). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14731 |
|
Out-of-Bounds Read in cpp (CVE-2017-14731)
vulnerability in cpp (CVE-2017-14731). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14733 |
|
Out-of-Bounds Read in c (CVE-2017-14733)
vulnerability in c (CVE-2017-14733). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14734 |
|
Buffer Overflow in c (CVE-2017-14734)
vulnerability in c (CVE-2017-14734). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14735 |
|
Cross-Site Scripting (XSS) in antisamy-project (CVE-2017-14735)
cross-site scripting in antisamy-project (CVE-2017-14735). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-5169 |
|
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
|
| CVE-2015-8375 |
|
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
|
| CVE-2015-5182 |
|
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
|
| CVE-2015-7293 |
|
Cross-Site Request Forgery (CSRF) in plone (CVE-2015-7293)
vulnerability in plone (CVE-2015-7293). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.0a1` or later.
|
| CVE-2017-14125 |
|
SQL Injection in wordpress (CVE-2017-14125)
SQL injection in wordpress (CVE-2017-14125). Successful exploitation can lead to full system takeover.
|
| CVE-2015-5282 |
|
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
|
| CVE-2015-6748 |
|
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
|
| CVE-2015-7316 |
|
Cross-Site Scripting (XSS) in plone (CVE-2015-7316)
cross-site scripting in plone (CVE-2015-7316). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3da710a2cd68587f0bf34f2e7ea1167d6eeee087, 4.0a1, 4.1a1, 4.2a1, 4.3a1, 4.3.7, 5.0rc2` or later.
|
| CVE-2010-3049 |
|
Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).
Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).
|
| CVE-2010-3050 |
|
Vulnerability in dos (CVE-2010-3050)
vulnerability in dos (CVE-2010-3050). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-1235 |
|
Vulnerability in dos (CVE-2017-1235)
vulnerability in dos (CVE-2017-1235). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14729 |
|
Buffer Overflow in c (CVE-2017-14729)
vulnerability in c (CVE-2017-14729). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1424 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2017-1424)
cross-site scripting in ibm (CVE-2017-1424). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9551 |
|
Cross-Site Scripting (XSS) in mahara (CVE-2017-9551)
cross-site scripting in mahara (CVE-2017-9551). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14506 |
|
Cross-Site Scripting (XSS) in geminabox-project (CVE-2017-14506)
cross-site scripting in geminabox-project (CVE-2017-14506). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14683 |
|
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
|
| CVE-2017-14723 |
|
SQL Injection in wordpress (CVE-2017-14723)
SQL injection in wordpress (CVE-2017-14723). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14718 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2017-14718)
cross-site scripting in wordpress (CVE-2017-14718). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14720 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2017-14720)
cross-site scripting in wordpress (CVE-2017-14720). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14721 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2017-14721)
cross-site scripting in wordpress (CVE-2017-14721). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14724 |
|
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
|
| CVE-2017-14726 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2017-14726)
cross-site scripting in wordpress (CVE-2017-14726). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14719 |
|
Path Traversal in wordpress (CVE-2017-14719)
path traversal in wordpress (CVE-2017-14719). Confidential information can be exposed externally.
|
| CVE-2017-14722 |
|
Path Traversal in wordpress (CVE-2017-14722)
path traversal in wordpress (CVE-2017-14722). Confidential information can be exposed externally.
|
| CVE-2017-14712 |
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
|
| CVE-2017-14713 |
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
|
| CVE-2017-14714 |
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
|
| CVE-2017-14715 |
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
|
| CVE-2017-14716 |
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
|
| CVE-2017-14717 |
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
|
| CVE-2017-14694 |
|
Buffer Overflow in c (CVE-2017-14694)
vulnerability in c (CVE-2017-14694). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6266 |
|
Vulnerability in dos (CVE-2017-6266)
vulnerability in dos (CVE-2017-6266). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6267 |
|
Vulnerability in dos (CVE-2017-6267)
vulnerability in dos (CVE-2017-6267). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6268 |
|
Vulnerability in dos (CVE-2017-6268)
vulnerability in dos (CVE-2017-6268). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6269 |
|
Vulnerability in dos (CVE-2017-6269)
vulnerability in dos (CVE-2017-6269). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6270 |
|
Vulnerability in dos (CVE-2017-6270)
vulnerability in dos (CVE-2017-6270). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6271 |
|
Vulnerability in dos (CVE-2017-6271)
vulnerability in dos (CVE-2017-6271). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6272 |
|
Vulnerability in dos (CVE-2017-6272)
vulnerability in dos (CVE-2017-6272). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6277 |
|
Vulnerability in dos (CVE-2017-6277)
vulnerability in dos (CVE-2017-6277). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14078 |
|
SQL Injection in sqli (CVE-2017-14078)
SQL injection in sqli (CVE-2017-14078). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14080 |
|
Authentication Bypass in trendmicro (CVE-2017-14080)
authentication bypass in trendmicro (CVE-2017-14080). Successful exploitation can lead to full system takeover.
|
| CVE-2017-3770 |
|
Vulnerability in privilege-escalation (CVE-2017-3770)
vulnerability in privilege-escalation (CVE-2017-3770). Successful exploitation can lead to full system takeover.
|