Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2017-9956 Vulnerability in schneider-electric (CVE-2017-9956)
vulnerability in schneider-electric (CVE-2017-9956). Risk of unauthorized operations or information disclosure.
CVE-2015-0238 Information Disclosure in privilege-escalation (CVE-2015-0238)
vulnerability in privilege-escalation (CVE-2015-0238). Risk of unauthorized operations or information disclosure.
CVE-2014-0997 Vulnerability in dos (CVE-2014-0997)
vulnerability in dos (CVE-2014-0997). Risk of unauthorized operations or information disclosure.
CVE-2014-8156 Vulnerability in dos (CVE-2014-8156)
vulnerability in dos (CVE-2014-8156). Successful exploitation can lead to full system takeover.
CVE-2017-14731 Out-of-Bounds Read in cpp (CVE-2017-14731)
vulnerability in cpp (CVE-2017-14731). Risk of unauthorized operations or information disclosure.
CVE-2017-14733 Out-of-Bounds Read in c (CVE-2017-14733)
vulnerability in c (CVE-2017-14733). Risk of unauthorized operations or information disclosure.
CVE-2017-14734 Buffer Overflow in c (CVE-2017-14734)
vulnerability in c (CVE-2017-14734). Successful exploitation can lead to full system takeover.
CVE-2017-14735 Cross-Site Scripting (XSS) in antisamy-project (CVE-2017-14735)
cross-site scripting in antisamy-project (CVE-2017-14735). Risk of unauthorized operations or information disclosure.
CVE-2015-5169 Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
CVE-2015-8375 Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
CVE-2015-5182 Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
CVE-2015-7293 Cross-Site Request Forgery (CSRF) in plone (CVE-2015-7293)
vulnerability in plone (CVE-2015-7293). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.0a1` or later.
CVE-2017-14125 SQL Injection in wordpress (CVE-2017-14125)
SQL injection in wordpress (CVE-2017-14125). Successful exploitation can lead to full system takeover.
CVE-2015-5282 Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
CVE-2015-6748 Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
CVE-2015-7316 Cross-Site Scripting (XSS) in plone (CVE-2015-7316)
cross-site scripting in plone (CVE-2015-7316). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3da710a2cd68587f0bf34f2e7ea1167d6eeee087, 4.0a1, 4.1a1, 4.2a1, 4.3a1, 4.3.7, 5.0rc2` or later.
CVE-2010-3049 Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).
Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).
CVE-2010-3050 Vulnerability in dos (CVE-2010-3050)
vulnerability in dos (CVE-2010-3050). Risk of unauthorized operations or information disclosure.
CVE-2017-1235 Vulnerability in dos (CVE-2017-1235)
vulnerability in dos (CVE-2017-1235). Risk of unauthorized operations or information disclosure.
CVE-2017-14729 Buffer Overflow in c (CVE-2017-14729)
vulnerability in c (CVE-2017-14729). Successful exploitation can lead to full system takeover.
CVE-2017-1424 Cross-Site Scripting (XSS) in ibm (CVE-2017-1424)
cross-site scripting in ibm (CVE-2017-1424). Risk of unauthorized operations or information disclosure.
CVE-2017-9551 Cross-Site Scripting (XSS) in mahara (CVE-2017-9551)
cross-site scripting in mahara (CVE-2017-9551). Risk of unauthorized operations or information disclosure.
CVE-2017-14506 Cross-Site Scripting (XSS) in geminabox-project (CVE-2017-14506)
cross-site scripting in geminabox-project (CVE-2017-14506). Risk of unauthorized operations or information disclosure.
CVE-2017-14683 geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
CVE-2017-14723 SQL Injection in wordpress (CVE-2017-14723)
SQL injection in wordpress (CVE-2017-14723). Successful exploitation can lead to full system takeover.
CVE-2017-14718 Cross-Site Scripting (XSS) in wordpress (CVE-2017-14718)
cross-site scripting in wordpress (CVE-2017-14718). Risk of unauthorized operations or information disclosure.
CVE-2017-14720 Cross-Site Scripting (XSS) in wordpress (CVE-2017-14720)
cross-site scripting in wordpress (CVE-2017-14720). Risk of unauthorized operations or information disclosure.
CVE-2017-14721 Cross-Site Scripting (XSS) in wordpress (CVE-2017-14721)
cross-site scripting in wordpress (CVE-2017-14721). Risk of unauthorized operations or information disclosure.
CVE-2017-14724 Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
CVE-2017-14726 Cross-Site Scripting (XSS) in wordpress (CVE-2017-14726)
cross-site scripting in wordpress (CVE-2017-14726). Risk of unauthorized operations or information disclosure.
CVE-2017-14719 Path Traversal in wordpress (CVE-2017-14719)
path traversal in wordpress (CVE-2017-14719). Confidential information can be exposed externally.
CVE-2017-14722 Path Traversal in wordpress (CVE-2017-14722)
path traversal in wordpress (CVE-2017-14722). Confidential information can be exposed externally.
CVE-2017-14712 In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
CVE-2017-14713 In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
CVE-2017-14714 In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
CVE-2017-14715 In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
CVE-2017-14716 In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
CVE-2017-14717 In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
CVE-2017-14694 Buffer Overflow in c (CVE-2017-14694)
vulnerability in c (CVE-2017-14694). Successful exploitation can lead to full system takeover.
CVE-2017-6266 Vulnerability in dos (CVE-2017-6266)
vulnerability in dos (CVE-2017-6266). Risk of unauthorized operations or information disclosure.
CVE-2017-6267 Vulnerability in dos (CVE-2017-6267)
vulnerability in dos (CVE-2017-6267). Risk of unauthorized operations or information disclosure.
CVE-2017-6268 Vulnerability in dos (CVE-2017-6268)
vulnerability in dos (CVE-2017-6268). Successful exploitation can lead to full system takeover.
CVE-2017-6269 Vulnerability in dos (CVE-2017-6269)
vulnerability in dos (CVE-2017-6269). Successful exploitation can lead to full system takeover.
CVE-2017-6270 Vulnerability in dos (CVE-2017-6270)
vulnerability in dos (CVE-2017-6270). Risk of unauthorized operations or information disclosure.
CVE-2017-6271 Vulnerability in dos (CVE-2017-6271)
vulnerability in dos (CVE-2017-6271). Risk of unauthorized operations or information disclosure.
CVE-2017-6272 Vulnerability in dos (CVE-2017-6272)
vulnerability in dos (CVE-2017-6272). Successful exploitation can lead to full system takeover.
CVE-2017-6277 Vulnerability in dos (CVE-2017-6277)
vulnerability in dos (CVE-2017-6277). Successful exploitation can lead to full system takeover.
CVE-2017-14078 SQL Injection in sqli (CVE-2017-14078)
SQL injection in sqli (CVE-2017-14078). Successful exploitation can lead to full system takeover.
CVE-2017-14080 Authentication Bypass in trendmicro (CVE-2017-14080)
authentication bypass in trendmicro (CVE-2017-14080). Successful exploitation can lead to full system takeover.
CVE-2017-3770 Vulnerability in privilege-escalation (CVE-2017-3770)
vulnerability in privilege-escalation (CVE-2017-3770). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →