Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-14035 |
|
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
|
| CVE-2015-7517 |
|
SQL Injection in wordpress (CVE-2015-7517)
SQL injection in wordpress (CVE-2015-7517). Successful exploitation can lead to full system takeover.
|
| CVE-2015-8352 |
|
Path Traversal in path-traversal (CVE-2015-8352)
path traversal in path-traversal (CVE-2015-8352). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12679 |
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
|
| CVE-2017-13669 |
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
|
| CVE-2015-5224 |
|
Vulnerability in kernel (CVE-2015-5224)
vulnerability in kernel (CVE-2015-5224). Successful exploitation can lead to full system takeover.
|
| CVE-2017-13137 |
|
The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
|
| CVE-2017-12791 |
|
Path Traversal in salt (CVE-2017-12791)
path traversal in salt (CVE-2017-12791). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2016.11.7, 2017.7.1` or later.
|
| CVE-2017-13139 |
|
Out-of-Bounds Read in c (CVE-2017-13139)
vulnerability in c (CVE-2017-13139). Successful exploitation can lead to full system takeover.
|
| CVE-2016-4460 |
|
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
|
| CVE-2017-12981 |
|
SQL Injection in sqli (CVE-2017-12981)
SQL injection in sqli (CVE-2017-12981). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11366 |
|
OS Command Injection in codiad (CVE-2017-11366)
OS command injection in codiad (CVE-2017-11366). Successful exploitation can lead to full system takeover.
|
| CVE-2007-5341 |
|
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
|
| CVE-2017-12776 |
|
SQL Injection in sqli (CVE-2017-12776)
SQL injection in sqli (CVE-2017-12776). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12943 |
|
Path Traversal in path-traversal (CVE-2017-12943)
path traversal in path-traversal (CVE-2017-12943). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12940 |
|
Out-of-Bounds Read in rarlab (CVE-2017-12940)
vulnerability in rarlab (CVE-2017-12940). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12941 |
|
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
|
| CVE-2017-12942 |
|
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
|
| CVE-2017-12939 |
|
Vulnerability in unity3d (CVE-2017-12939)
vulnerability in unity3d (CVE-2017-12939). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12932 |
|
Use-After-Free in CVE-2017-12932 (CVE-2017-12932)
vulnerability in CVE-2017-12932 (CVE-2017-12932). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12933 |
|
Out-of-Bounds Read in CVE-2017-12933 (CVE-2017-12933)
vulnerability in CVE-2017-12933 (CVE-2017-12933). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12908 |
|
SQL Injection in sqli (CVE-2017-12908)
SQL injection in sqli (CVE-2017-12908). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12909 |
|
SQL Injection in sqli (CVE-2017-12909)
SQL injection in sqli (CVE-2017-12909). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12910 |
|
SQL Injection in sqli (CVE-2017-12910)
SQL injection in sqli (CVE-2017-12910). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9800 |
|
Vulnerability in apache (CVE-2017-9800)
vulnerability in apache (CVE-2017-9800). Successful exploitation can lead to full system takeover.
|
| CVE-2017-3124 |
|
Buffer Overflow in adobe (CVE-2017-3124)
vulnerability in adobe (CVE-2017-3124). Successful exploitation can lead to full system takeover.
|
| CVE-2016-5018 |
|
Vulnerability in apache (CVE-2016-5018)
vulnerability in apache (CVE-2016-5018). Confidential information can be exposed externally.
|
| CVE-2017-12774 |
|
SQL Injection in finecms-project (CVE-2017-12774)
SQL injection in finecms-project (CVE-2017-12774). Successful exploitation can lead to full system takeover.
|
| CVE-2012-0803 |
|
Authentication Bypass in apache (CVE-2012-0803)
authentication bypass in apache (CVE-2012-0803). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11151 |
|
Authentication Bypass in synology (CVE-2017-11151)
authentication bypass in synology (CVE-2017-11151). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11153 |
|
Unsafe Deserialization in deserialization (CVE-2017-11153)
vulnerability in deserialization (CVE-2017-11153). Successful exploitation can lead to full system takeover.
|
| CVE-2017-3632 |
|
Vulnerability in c (CVE-2017-3632)
vulnerability in c (CVE-2017-3632). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10137 |
|
Vulnerability in c (CVE-2017-10137)
vulnerability in c (CVE-2017-10137). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6747 |
|
Authentication Bypass in express (CVE-2017-6747)
authentication bypass in express (CVE-2017-6747). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11393 |
|
Vulnerability in trendmicro (CVE-2017-11393)
vulnerability in trendmicro (CVE-2017-11393). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11394 |
|
Vulnerability in trendmicro (CVE-2017-11394)
vulnerability in trendmicro (CVE-2017-11394). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8390 |
|
Vulnerability in paloaltonetworks (CVE-2017-8390)
vulnerability in paloaltonetworks (CVE-2017-8390). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12199 |
|
SQL Injection in wordpress (CVE-2017-12199)
SQL injection in wordpress (CVE-2017-12199). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4923 |
|
Information Disclosure in vmware (CVE-2017-4923)
vulnerability in vmware (CVE-2017-4923). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12065 |
|
Vulnerability in cacti (CVE-2017-12065)
vulnerability in cacti (CVE-2017-12065). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4919 |
|
Vulnerability in vmware (CVE-2017-4919)
vulnerability in vmware (CVE-2017-4919). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11694 |
|
Vulnerability in apache (CVE-2017-11694)
vulnerability in apache (CVE-2017-11694). Confidential information can be exposed externally.
|
| CVE-2017-11184 |
|
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
|
| CVE-2017-11715 |
|
Code Injection in metinfo-project (CVE-2017-11715)
code injection in metinfo-project (CVE-2017-11715). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11631 |
|
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
|
| CVE-2017-11324 |
|
SQL Injection in sqli (CVE-2017-11324)
SQL injection in sqli (CVE-2017-11324). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11582 |
|
SQL Injection in sqli (CVE-2017-11582)
SQL injection in sqli (CVE-2017-11582). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11583 |
|
SQL Injection in sqli (CVE-2017-11583)
SQL injection in sqli (CVE-2017-11583). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11584 |
|
SQL Injection in sqli (CVE-2017-11584)
SQL injection in sqli (CVE-2017-11584). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11585 |
|
Code Injection in finecms (CVE-2017-11585)
code injection in finecms (CVE-2017-11585). Successful exploitation can lead to full system takeover.
|