Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: products Clear
ID Title
CVE-2017-14035 CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
CVE-2015-7517 SQL Injection in wordpress (CVE-2015-7517)
SQL injection in wordpress (CVE-2015-7517). Successful exploitation can lead to full system takeover.
CVE-2015-8352 Path Traversal in path-traversal (CVE-2015-8352)
path traversal in path-traversal (CVE-2015-8352). Successful exploitation can lead to full system takeover.
CVE-2017-12679 SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
CVE-2017-13669 SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
CVE-2015-5224 Vulnerability in kernel (CVE-2015-5224)
vulnerability in kernel (CVE-2015-5224). Successful exploitation can lead to full system takeover.
CVE-2017-13137 The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
CVE-2017-12791 Path Traversal in salt (CVE-2017-12791)
path traversal in salt (CVE-2017-12791). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2016.11.7, 2017.7.1` or later.
CVE-2017-13139 Out-of-Bounds Read in c (CVE-2017-13139)
vulnerability in c (CVE-2017-13139). Successful exploitation can lead to full system takeover.
CVE-2016-4460 Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
CVE-2017-12981 SQL Injection in sqli (CVE-2017-12981)
SQL injection in sqli (CVE-2017-12981). Successful exploitation can lead to full system takeover.
CVE-2017-11366 OS Command Injection in codiad (CVE-2017-11366)
OS command injection in codiad (CVE-2017-11366). Successful exploitation can lead to full system takeover.
CVE-2007-5341 Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
CVE-2017-12776 SQL Injection in sqli (CVE-2017-12776)
SQL injection in sqli (CVE-2017-12776). Successful exploitation can lead to full system takeover.
CVE-2017-12943 Path Traversal in path-traversal (CVE-2017-12943)
path traversal in path-traversal (CVE-2017-12943). Successful exploitation can lead to full system takeover.
CVE-2017-12940 Out-of-Bounds Read in rarlab (CVE-2017-12940)
vulnerability in rarlab (CVE-2017-12940). Successful exploitation can lead to full system takeover.
CVE-2017-12941 libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
CVE-2017-12942 libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
CVE-2017-12939 Vulnerability in unity3d (CVE-2017-12939)
vulnerability in unity3d (CVE-2017-12939). Successful exploitation can lead to full system takeover.
CVE-2017-12932 Use-After-Free in CVE-2017-12932 (CVE-2017-12932)
vulnerability in CVE-2017-12932 (CVE-2017-12932). Successful exploitation can lead to full system takeover.
CVE-2017-12933 Out-of-Bounds Read in CVE-2017-12933 (CVE-2017-12933)
vulnerability in CVE-2017-12933 (CVE-2017-12933). Successful exploitation can lead to full system takeover.
CVE-2017-12908 SQL Injection in sqli (CVE-2017-12908)
SQL injection in sqli (CVE-2017-12908). Successful exploitation can lead to full system takeover.
CVE-2017-12909 SQL Injection in sqli (CVE-2017-12909)
SQL injection in sqli (CVE-2017-12909). Successful exploitation can lead to full system takeover.
CVE-2017-12910 SQL Injection in sqli (CVE-2017-12910)
SQL injection in sqli (CVE-2017-12910). Successful exploitation can lead to full system takeover.
CVE-2017-9800 Vulnerability in apache (CVE-2017-9800)
vulnerability in apache (CVE-2017-9800). Successful exploitation can lead to full system takeover.
CVE-2017-3124 Buffer Overflow in adobe (CVE-2017-3124)
vulnerability in adobe (CVE-2017-3124). Successful exploitation can lead to full system takeover.
CVE-2016-5018 Vulnerability in apache (CVE-2016-5018)
vulnerability in apache (CVE-2016-5018). Confidential information can be exposed externally.
CVE-2017-12774 SQL Injection in finecms-project (CVE-2017-12774)
SQL injection in finecms-project (CVE-2017-12774). Successful exploitation can lead to full system takeover.
CVE-2012-0803 Authentication Bypass in apache (CVE-2012-0803)
authentication bypass in apache (CVE-2012-0803). Successful exploitation can lead to full system takeover.
CVE-2017-11151 Authentication Bypass in synology (CVE-2017-11151)
authentication bypass in synology (CVE-2017-11151). Successful exploitation can lead to full system takeover.
CVE-2017-11153 Unsafe Deserialization in deserialization (CVE-2017-11153)
vulnerability in deserialization (CVE-2017-11153). Successful exploitation can lead to full system takeover.
CVE-2017-3632 Vulnerability in c (CVE-2017-3632)
vulnerability in c (CVE-2017-3632). Successful exploitation can lead to full system takeover.
CVE-2017-10137 Vulnerability in c (CVE-2017-10137)
vulnerability in c (CVE-2017-10137). Successful exploitation can lead to full system takeover.
CVE-2017-6747 Authentication Bypass in express (CVE-2017-6747)
authentication bypass in express (CVE-2017-6747). Successful exploitation can lead to full system takeover.
CVE-2017-11393 Vulnerability in trendmicro (CVE-2017-11393)
vulnerability in trendmicro (CVE-2017-11393). Successful exploitation can lead to full system takeover.
CVE-2017-11394 Vulnerability in trendmicro (CVE-2017-11394)
vulnerability in trendmicro (CVE-2017-11394). Successful exploitation can lead to full system takeover.
CVE-2017-8390 Vulnerability in paloaltonetworks (CVE-2017-8390)
vulnerability in paloaltonetworks (CVE-2017-8390). Successful exploitation can lead to full system takeover.
CVE-2017-12199 SQL Injection in wordpress (CVE-2017-12199)
SQL injection in wordpress (CVE-2017-12199). Successful exploitation can lead to full system takeover.
CVE-2017-4923 Information Disclosure in vmware (CVE-2017-4923)
vulnerability in vmware (CVE-2017-4923). Successful exploitation can lead to full system takeover.
CVE-2017-12065 Vulnerability in cacti (CVE-2017-12065)
vulnerability in cacti (CVE-2017-12065). Successful exploitation can lead to full system takeover.
CVE-2017-4919 Vulnerability in vmware (CVE-2017-4919)
vulnerability in vmware (CVE-2017-4919). Successful exploitation can lead to full system takeover.
CVE-2017-11694 Vulnerability in apache (CVE-2017-11694)
vulnerability in apache (CVE-2017-11694). Confidential information can be exposed externally.
CVE-2017-11184 SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
CVE-2017-11715 Code Injection in metinfo-project (CVE-2017-11715)
code injection in metinfo-project (CVE-2017-11715). Successful exploitation can lead to full system takeover.
CVE-2017-11631 dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
CVE-2017-11324 SQL Injection in sqli (CVE-2017-11324)
SQL injection in sqli (CVE-2017-11324). Successful exploitation can lead to full system takeover.
CVE-2017-11582 SQL Injection in sqli (CVE-2017-11582)
SQL injection in sqli (CVE-2017-11582). Successful exploitation can lead to full system takeover.
CVE-2017-11583 SQL Injection in sqli (CVE-2017-11583)
SQL injection in sqli (CVE-2017-11583). Successful exploitation can lead to full system takeover.
CVE-2017-11584 SQL Injection in sqli (CVE-2017-11584)
SQL injection in sqli (CVE-2017-11584). Successful exploitation can lead to full system takeover.
CVE-2017-11585 Code Injection in finecms (CVE-2017-11585)
code injection in finecms (CVE-2017-11585). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →