Latest CVE Feed
-
3.3
LOWCVE-2012-6655
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.... Read more
- EPSS Score: %0.03
- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6652
Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.... Read more
Affected Products : page_flip_book- EPSS Score: %2.26
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6649
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.... Read more
Affected Products : wp_gpx_maps- EPSS Score: %44.94
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2012-6639
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.... Read more
- EPSS Score: %1.20
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2012-6614
D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.... Read more
- EPSS Score: %8.06
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2012-6613
D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.... Read more
- EPSS Score: %0.98
- Published: Jan. 25, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-6611
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without se... Read more
- EPSS Score: %1.01
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2012-6610
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.... Read more
- EPSS Score: %2.23
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-6609
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.... Read more
- EPSS Score: %0.41
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6494
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.... Read more
Affected Products : nexpose- EPSS Score: %0.53
- Published: Jan. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6451
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability... Read more
- EPSS Score: %1.80
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2012-6449
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.... Read more
- EPSS Score: %0.18
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6448
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : webhost_manager- EPSS Score: %0.26
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6347
Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the conversationContext parameter to (1) admin/auditTrail.jsf,... Read more
Affected Products : fortidb- EPSS Score: %0.23
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6346
Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate.... Read more
Affected Products : fortiweb- EPSS Score: %0.26
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-6345
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.... Read more
Affected Products : zenworks_configuration_management- EPSS Score: %0.51
- Published: Jan. 25, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6344
Novell ZENworks Configuration Management before 11.2.4 allows XSS.... Read more
Affected Products : zenworks_configuration_management- EPSS Score: %0.23
- Published: Jan. 25, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2012-6341
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a di... Read more
- EPSS Score: %0.47
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2012-6340
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.... Read more
- EPSS Score: %0.24
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-6309
A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service.... Read more
Affected Products : arctic_torrent- EPSS Score: %0.33
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024