Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-16920 |
|
Vulnerability in finecms (CVE-2017-16920)
vulnerability in finecms (CVE-2017-16920). Successful exploitation can lead to full system takeover.
|
| CVE-2017-16866 |
|
Cross-Site Scripting (XSS) in finecms (CVE-2017-16866)
cross-site scripting in finecms (CVE-2017-16866). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14195 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14195)
cross-site scripting in finecms-project (CVE-2017-14195). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2017-14194 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14194)
cross-site scripting in finecms-project (CVE-2017-14194). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2017-14193 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14193)
cross-site scripting in finecms-project (CVE-2017-14193). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2017-14192 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14192)
cross-site scripting in finecms-project (CVE-2017-14192). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-13697 |
|
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
|
| CVE-2017-12774 |
|
SQL Injection in finecms-project (CVE-2017-12774)
SQL injection in finecms-project (CVE-2017-12774). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11629 |
|
Cross-Site Scripting (XSS) in c (CVE-2017-11629)
cross-site scripting in c (CVE-2017-11629). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11581 |
|
Cross-Site Scripting (XSS) in finecms (CVE-2017-11581)
cross-site scripting in finecms (CVE-2017-11581). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11586 |
|
Open Redirect in finecms (CVE-2017-11586)
vulnerability in finecms (CVE-2017-11586). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11585 |
|
Code Injection in finecms (CVE-2017-11585)
code injection in finecms (CVE-2017-11585). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11584 |
|
SQL Injection in sqli (CVE-2017-11584)
SQL injection in sqli (CVE-2017-11584). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11583 |
|
SQL Injection in sqli (CVE-2017-11583)
SQL injection in sqli (CVE-2017-11583). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11582 |
|
SQL Injection in sqli (CVE-2017-11582)
SQL injection in sqli (CVE-2017-11582). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11202 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11202)
cross-site scripting in finecms-project (CVE-2017-11202). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11201 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11201)
cross-site scripting in finecms-project (CVE-2017-11201). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11200 |
|
SQL Injection in sqli (CVE-2017-11200)
SQL injection in sqli (CVE-2017-11200). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11198 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11198)
cross-site scripting in finecms-project (CVE-2017-11198). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11167 |
|
Code Injection in finecms-project (CVE-2017-11167)
code injection in finecms-project (CVE-2017-11167). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11180 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11180)
cross-site scripting in finecms-project (CVE-2017-11180). Risk of unauthorized operations or information disclosure. Exploitable via `User-Agent header`.
|
| CVE-2017-11179 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11179)
cross-site scripting in finecms-project (CVE-2017-11179). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11178 |
|
Vulnerability in finecms-project (CVE-2017-11178)
vulnerability in finecms-project (CVE-2017-11178). Data can be tampered with by attackers.
|
| CVE-2017-10968 |
|
Code Injection in finecms-project (CVE-2017-10968)
code injection in finecms-project (CVE-2017-10968). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10973 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2017-10973)
SSRF in ssrf (CVE-2017-10973). Data can be tampered with by attackers. Exploitable via `Host header`.
|
| CVE-2017-10967 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-10967)
cross-site scripting in finecms-project (CVE-2017-10967). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9252 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-9252)
cross-site scripting in finecms-project (CVE-2017-9252). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9251 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-9251)
cross-site scripting in finecms-project (CVE-2017-9251). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6511 |
|
Cross-Site Scripting (XSS) in finecms-project (CVE-2017-6511)
cross-site scripting in finecms-project (CVE-2017-6511). Risk of unauthorized operations or information disclosure.
|