Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2012-4603

    Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.... Read more

    Affected Products : windows receiver xenapp_online
    • EPSS Score: %5.78
    • Published: Jan. 10, 2020
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2012-4576

    FreeBSD: Input Validation Flaw allows local users to gain elevated privileges... Read more

    Affected Products : debian_linux freebsd
    • EPSS Score: %0.10
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4526

    piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)... Read more

    Affected Products : piwigo
    • EPSS Score: %0.43
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4525

    piwigo has XSS in password.php... Read more

    Affected Products : piwigo
    • EPSS Score: %0.43
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-4524

    xlockmore before 5.43 'dclock' security bypass vulnerability... Read more

    Affected Products : fedora xlockmore
    • EPSS Score: %0.67
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4519

    Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.... Read more

    Affected Products : zenphoto
    • EPSS Score: %0.24
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2012-4512

    The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."... Read more

    • EPSS Score: %9.04
    • Published: Feb. 08, 2020
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2012-4480

    mom creates world-writable pid files in /var/run... Read more

    Affected Products : fedora mom
    • EPSS Score: %0.13
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4451

    Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorato... Read more

    Affected Products : enterprise_linux fedora zend_framework
    • EPSS Score: %1.78
    • Published: Jan. 03, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4441

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.... Read more

    Affected Products : jenkins
    • EPSS Score: %1.50
    • Published: Nov. 18, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4440

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.... Read more

    Affected Products : jenkins
    • EPSS Score: %1.50
    • Published: Nov. 18, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4439

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.... Read more

    Affected Products : jenkins
    • EPSS Score: %0.44
    • Published: Nov. 18, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2012-4438

    Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.... Read more

    Affected Products : jenkins
    • EPSS Score: %1.12
    • Published: Nov. 18, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2012-4434

    fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.... Read more

    Affected Products : fwknop
    • EPSS Score: %5.49
    • Published: Jan. 09, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-4428

    openslp: SLPIntersectStringList()' Function has a DoS vulnerability... Read more

    Affected Products : ubuntu_linux fedora debian_linux openslp
    • EPSS Score: %46.22
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-4420

    An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements righ... Read more

    Affected Products : jdk
    • EPSS Score: %1.07
    • Published: Dec. 26, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2012-4385

    letodms 3.3.6 has CSRF via change password... Read more

    Affected Products : debian_linux letodms
    • EPSS Score: %0.23
    • Published: Nov. 13, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-4384

    letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar... Read more

    Affected Products : debian_linux letodms
    • EPSS Score: %0.45
    • Published: Nov. 13, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2012-4383

    contao prior to 2.11.4 has a sql injection vulnerability... Read more

    Affected Products : contao
    • EPSS Score: %0.26
    • Published: Jan. 29, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2012-4381

    MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a ... Read more

    Affected Products : mediawiki
    • EPSS Score: %4.12
    • Published: Feb. 08, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291616 Results