Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-1489 |
|
Open Redirect in ibm (CVE-2017-1489)
vulnerability in ibm (CVE-2017-1489). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10844 |
|
Code Injection in basercms (CVE-2017-10844)
code injection in basercms (CVE-2017-10844). Successful exploitation can lead to full system takeover.
|
| CVE-2017-13715 |
|
Vulnerability in c (CVE-2017-13715)
vulnerability in c (CVE-2017-13715). Successful exploitation can lead to full system takeover.
|
| CVE-2016-2970 |
|
Information Disclosure in ibm (CVE-2016-2970)
vulnerability in ibm (CVE-2016-2970). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-9732 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2016-9732)
cross-site scripting in ibm (CVE-2016-9732). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-13716 |
|
Vulnerability in c (CVE-2017-13716)
vulnerability in c (CVE-2017-13716). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-3735 |
|
Buffer Overflow in openssl (CVE-2017-3735)
vulnerability in openssl (CVE-2017-3735). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12876 |
|
Out-of-Bounds Write in c (CVE-2017-12876)
out-of-bounds write in c (CVE-2017-12876). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12877 |
|
Use-After-Free in c (CVE-2017-12877)
vulnerability in c (CVE-2017-12877). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-0634 |
|
OS Command Injection in gnu (CVE-2016-0634)
OS command injection in gnu (CVE-2016-0634). Successful exploitation can lead to full system takeover.
|
| CVE-2014-9483 |
|
Emacs 24.4 allows remote attackers to bypass security restrictions.
Emacs 24.4 allows remote attackers to bypass security restrictions.
|
| CVE-2014-8871 |
|
Path Traversal in path-traversal (CVE-2014-8871)
path traversal in path-traversal (CVE-2014-8871). Confidential information can be exposed externally.
|
| CVE-2014-8900 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2014-8900)
vulnerability in csrf (CVE-2014-8900). Successful exploitation can lead to full system takeover.
|
| CVE-2015-0101 |
|
Cross-Site Scripting (XSS) in express (CVE-2015-0101)
cross-site scripting in express (CVE-2015-0101). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-0114 |
|
Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.
Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.
|
| CVE-2014-9469 |
|
Cross-Site Scripting (XSS) in vbulletin (CVE-2014-9469)
cross-site scripting in vbulletin (CVE-2014-9469). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-4925 |
|
Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.
Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.
|
| CVE-2017-13710 |
|
Vulnerability in c (CVE-2017-13710)
vulnerability in c (CVE-2017-13710). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-7857 |
|
Authentication Bypass in d-link (CVE-2014-7857)
authentication bypass in d-link (CVE-2014-7857). Successful exploitation can lead to full system takeover.
|
| CVE-2014-7858 |
|
Authentication Bypass in d-link (CVE-2014-7858)
authentication bypass in d-link (CVE-2014-7858). Successful exploitation can lead to full system takeover.
|
| CVE-2014-7859 |
|
Buffer Overflow in d-link (CVE-2014-7859)
vulnerability in d-link (CVE-2014-7859). Successful exploitation can lead to full system takeover.
|
| CVE-2014-9637 |
|
Vulnerability in dos (CVE-2014-9637)
vulnerability in dos (CVE-2014-9637). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-1395 |
|
Path Traversal in path-traversal (CVE-2015-1395)
path traversal in path-traversal (CVE-2015-1395). Data can be tampered with by attackers.
|
| CVE-2014-9564 |
|
Vulnerability in ibm (CVE-2014-9564)
vulnerability in ibm (CVE-2014-9564). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-4017 |
|
Vulnerability in salt (CVE-2015-4017)
vulnerability in salt (CVE-2015-4017). Data can be tampered with by attackers. Mitigation: upgrade to `2014.7.6` or later.
|
| CVE-2014-7860 |
|
Information Disclosure in d-link (CVE-2014-7860)
vulnerability in d-link (CVE-2014-7860). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-3211 |
|
php-fpm allows local users to write to or create arbitrary files via a symlink attack.
php-fpm allows local users to write to or create arbitrary files via a symlink attack.
|
| CVE-2015-4180 |
|
Path Traversal in path-traversal (CVE-2015-4180)
path traversal in path-traversal (CVE-2015-4180). Confidential information can be exposed externally.
|
| CVE-2015-4181 |
|
Path Traversal in path-traversal (CVE-2015-4181)
path traversal in path-traversal (CVE-2015-4181). Confidential information can be exposed externally.
|
| CVE-2015-3206 |
|
Authentication Bypass in pykerberos (CVE-2015-3206)
authentication bypass in pykerberos (CVE-2015-3206). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.1.6` or later.
|
| CVE-2017-13697 |
|
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
|
| CVE-2017-13693 |
|
Information Disclosure in c (CVE-2017-13693)
vulnerability in c (CVE-2017-13693). Confidential information can be exposed externally.
|
| CVE-2017-13694 |
|
Information Disclosure in c (CVE-2017-13694)
vulnerability in c (CVE-2017-13694). Confidential information can be exposed externally.
|
| CVE-2017-13695 |
|
Information Disclosure in c (CVE-2017-13695)
vulnerability in c (CVE-2017-13695). Confidential information can be exposed externally.
|
| CVE-2017-13686 |
|
Vulnerability in c (CVE-2017-13686)
vulnerability in c (CVE-2017-13686). Successful exploitation can lead to full system takeover.
|
| CVE-2015-8352 |
|
Path Traversal in path-traversal (CVE-2015-8352)
path traversal in path-traversal (CVE-2015-8352). Successful exploitation can lead to full system takeover.
|
| CVE-2015-8355 |
|
SQL Injection in sqli (CVE-2015-8355)
SQL injection in sqli (CVE-2015-8355). Successful exploitation can lead to full system takeover.
|
| CVE-2015-1800 |
|
Information Disclosure in samsung (CVE-2015-1800)
vulnerability in samsung (CVE-2015-1800). Confidential information can be exposed externally.
|
| CVE-2015-1801 |
|
Buffer Overflow in dos (CVE-2015-1801)
vulnerability in dos (CVE-2015-1801). Successful exploitation can lead to full system takeover.
|
| CVE-2015-7896 |
|
Buffer Overflow in dos (CVE-2015-7896)
vulnerability in dos (CVE-2015-7896). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12879 |
|
Cross-Site Scripting (XSS) in paessler (CVE-2017-12879)
cross-site scripting in paessler (CVE-2017-12879). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-13671 |
|
Cross-Site Scripting (XSS) in misp (CVE-2017-13671)
cross-site scripting in misp (CVE-2017-13671). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9555 |
|
Cross-Site Scripting (XSS) in synology (CVE-2017-9555)
cross-site scripting in synology (CVE-2017-9555). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9511 |
|
Path Traversal in path-traversal (CVE-2017-9511)
path traversal in path-traversal (CVE-2017-9511). Confidential information can be exposed externally.
|
| CVE-2017-9507 |
|
Cross-Site Scripting (XSS) in atlassian (CVE-2017-9507)
cross-site scripting in atlassian (CVE-2017-9507). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9508 |
|
Cross-Site Scripting (XSS) in atlassian (CVE-2017-9508)
cross-site scripting in atlassian (CVE-2017-9508). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9509 |
|
Cross-Site Scripting (XSS) in atlassian (CVE-2017-9509)
cross-site scripting in atlassian (CVE-2017-9509). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9510 |
|
Cross-Site Scripting (XSS) in atlassian (CVE-2017-9510)
cross-site scripting in atlassian (CVE-2017-9510). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9512 |
|
Information Disclosure in atlassian (CVE-2017-9512)
vulnerability in atlassian (CVE-2017-9512). Confidential information can be exposed externally.
|
| CVE-2017-12679 |
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
|