Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-9764 |
|
Cross-Site Scripting (XSS) in metinfo (CVE-2017-9764)
cross-site scripting in metinfo (CVE-2017-9764). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11444 |
|
SQL Injection in sqli (CVE-2017-11444)
SQL injection in sqli (CVE-2017-11444). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11445 |
|
SQL Injection in sqli (CVE-2017-11445)
SQL injection in sqli (CVE-2017-11445). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10801 |
|
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.
|
| CVE-2017-11439 |
|
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
|
| CVE-2017-11441 |
|
Cross-Site Scripting (XSS) in cpanel (CVE-2017-11441)
cross-site scripting in cpanel (CVE-2017-11441). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11440 |
|
Path Traversal in path-traversal (CVE-2017-11440)
path traversal in path-traversal (CVE-2017-11440). Confidential information can be exposed externally.
|
| CVE-2017-11456 |
|
Path Traversal in path-traversal (CVE-2017-11456)
path traversal in path-traversal (CVE-2017-11456). Confidential information can be exposed externally.
|
| CVE-2017-11435 |
|
Information Disclosure in humaxdigital (CVE-2017-11435)
vulnerability in humaxdigital (CVE-2017-11435). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11447 |
|
Vulnerability in c (CVE-2017-11447)
vulnerability in c (CVE-2017-11447). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11449 |
|
Vulnerability in c (CVE-2017-11449)
vulnerability in c (CVE-2017-11449). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11450 |
|
Vulnerability in c (CVE-2017-11450)
vulnerability in c (CVE-2017-11450). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11423 |
|
Out-of-Bounds Read in c (CVE-2017-11423)
vulnerability in c (CVE-2017-11423). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10708 |
|
Path Traversal in path-traversal (CVE-2017-10708)
path traversal in path-traversal (CVE-2017-10708). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5247 |
|
Cross-Site Scripting (XSS) in biscom (CVE-2017-5247)
cross-site scripting in biscom (CVE-2017-5247). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10962 |
|
REDCap before 7.5.1 has XSS via the query string.
REDCap before 7.5.1 has XSS via the query string.
|
| CVE-2017-10961 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-10961)
vulnerability in csrf (CVE-2017-10961). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11412 |
|
SQL Injection in sqli (CVE-2017-11412)
SQL injection in sqli (CVE-2017-11412). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11413 |
|
SQL Injection in sqli (CVE-2017-11413)
SQL injection in sqli (CVE-2017-11413). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11414 |
|
SQL Injection in sqli (CVE-2017-11414)
SQL injection in sqli (CVE-2017-11414). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11415 |
|
SQL Injection in sqli (CVE-2017-11415)
SQL injection in sqli (CVE-2017-11415). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11416 |
|
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
|
| CVE-2017-11417 |
|
SQL Injection in sqli (CVE-2017-11417)
SQL injection in sqli (CVE-2017-11417). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11418 |
|
SQL Injection in sqli (CVE-2017-11418)
SQL injection in sqli (CVE-2017-11418). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11419 |
|
SQL Injection in sqli (CVE-2017-11419)
SQL injection in sqli (CVE-2017-11419). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8896 |
|
Cross-Site Scripting (XSS) in owncloud (CVE-2017-8896)
cross-site scripting in owncloud (CVE-2017-8896). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9338 |
|
Cross-Site Scripting (XSS) in owncloud (CVE-2017-9338)
cross-site scripting in owncloud (CVE-2017-9338). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9609 |
|
Cross-Site Scripting (XSS) in blackcat-cms (CVE-2017-9609)
cross-site scripting in blackcat-cms (CVE-2017-9609). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9813 |
|
Cross-Site Scripting (XSS) in kaspersky (CVE-2017-9813)
cross-site scripting in kaspersky (CVE-2017-9813). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9934 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2017-9934)
cross-site scripting in csrf (CVE-2017-9934). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9810 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-9810)
vulnerability in csrf (CVE-2017-9810). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9669 |
|
Buffer Overflow in dos (CVE-2017-9669)
vulnerability in dos (CVE-2017-9669). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9671 |
|
Buffer Overflow in dos (CVE-2017-9671)
vulnerability in dos (CVE-2017-9671). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11399 |
|
Out-of-Bounds Read in c (CVE-2017-11399)
vulnerability in c (CVE-2017-11399). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9639 |
|
Buffer Overflow in fujielectric (CVE-2017-9639)
vulnerability in fujielectric (CVE-2017-9639). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11127 |
|
Cross-Site Scripting (XSS) in boltcms (CVE-2017-11127)
cross-site scripting in boltcms (CVE-2017-11127). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11128 |
|
Cross-Site Scripting (XSS) in boltcms (CVE-2017-11128)
cross-site scripting in boltcms (CVE-2017-11128). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10978 |
|
Buffer Overflow in dos (CVE-2017-10978)
vulnerability in dos (CVE-2017-10978). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10979 |
|
Out-of-Bounds Write in dos (CVE-2017-10979)
out-of-bounds write in dos (CVE-2017-10979). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10980 |
|
Vulnerability in dos (CVE-2017-10980)
vulnerability in dos (CVE-2017-10980). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10981 |
|
Vulnerability in dos (CVE-2017-10981)
vulnerability in dos (CVE-2017-10981). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10982 |
|
Out-of-Bounds Read in dos (CVE-2017-10982)
vulnerability in dos (CVE-2017-10982). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10983 |
|
Buffer Overflow in dos (CVE-2017-10983)
vulnerability in dos (CVE-2017-10983). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10984 |
|
Out-of-Bounds Write in c (CVE-2017-10984)
out-of-bounds write in c (CVE-2017-10984). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10985 |
|
Vulnerability in dos (CVE-2017-10985)
vulnerability in dos (CVE-2017-10985). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10986 |
|
Vulnerability in dos (CVE-2017-10986)
vulnerability in dos (CVE-2017-10986). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10987 |
|
Out-of-Bounds Read in dos (CVE-2017-10987)
vulnerability in dos (CVE-2017-10987). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11367 |
|
Out-of-Bounds Read in dos (CVE-2017-11367)
vulnerability in dos (CVE-2017-11367). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8000 |
|
Cross-Site Scripting (XSS) in emc (CVE-2017-8000)
cross-site scripting in emc (CVE-2017-8000). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8005 |
|
Cross-Site Scripting (XSS) in emc (CVE-2017-8005)
cross-site scripting in emc (CVE-2017-8005). Risk of unauthorized operations or information disclosure.
|