Latest CVE Feed
-
7.1
HIGHCVE-2013-0159
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg.... Read more
Affected Products : fedora- EPSS Score: %0.04
- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2012-6721
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4.... Read more
Affected Products : socialengine- EPSS Score: %0.11
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6720
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to... Read more
Affected Products : socialengine- EPSS Score: %0.22
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6719
The sharebar plugin before 1.2.2 for WordPress has SQL injection.... Read more
Affected Products : sharebar- EPSS Score: %0.55
- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6718
The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.... Read more
Affected Products : sharebar- EPSS Score: %0.19
- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6717
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.... Read more
Affected Products : redirection- EPSS Score: %0.19
- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6716
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.... Read more
- EPSS Score: %0.19
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6715
The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.... Read more
Affected Products : formbuilder- EPSS Score: %0.19
- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6714
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.... Read more
Affected Products : count_per_day- EPSS Score: %0.19
- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6713
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.... Read more
Affected Products : job_manager- EPSS Score: %0.19
- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6712
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.... Read more
Affected Products : linux_kernel- EPSS Score: %0.78
- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2012-6711
A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print ... Read more
- EPSS Score: %0.11
- Published: Jun. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6710
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.... Read more
Affected Products : extplorer- EPSS Score: %6.56
- Published: Oct. 07, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2012-6709
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.... Read more
- EPSS Score: %0.20
- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6708
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for th... Read more
Affected Products : jquery- EPSS Score: %0.88
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-6685
Nokogiri before 1.5.4 is vulnerable to XXE attacks... Read more
- EPSS Score: %0.32
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6682
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter.... Read more
Affected Products : vbdownloads_module- EPSS Score: %0.29
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6671
Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attackers to inject arbitrary web script or HTML via the (1) mon... Read more
Affected Products : forumon_rpg_module- EPSS Score: %0.27
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6670
Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the reason parameter in (1) actions/nominatemedal.php or (2) ... Read more
Affected Products : vbactivity_module- EPSS Score: %0.27
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-6668
Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the (1) reportreason parameter in actions/d... Read more
Affected Products : vbshout_module- EPSS Score: %0.27
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024