Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2011-4632

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message.... Read more

    Affected Products : typo3
    • EPSS Score: %0.20
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2011-4631

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extension recycler.... Read more

    Affected Products : typo3
    • EPSS Score: %0.20
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2011-4630

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browse_links wizard.... Read more

    Affected Products : typo3
    • EPSS Score: %0.20
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2011-4629

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the admin panel.... Read more

    Affected Products : typo3
    • EPSS Score: %0.20
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2011-4628

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.... Read more

    Affected Products : typo3
    • EPSS Score: %0.71
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2011-4627

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.... Read more

    Affected Products : typo3
    • EPSS Score: %0.33
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2011-4626

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.... Read more

    Affected Products : typo3
    • EPSS Score: %0.33
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2011-4625

    simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.... Read more

    Affected Products : debian_linux simplesamlphp
    • EPSS Score: %0.27
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2011-4574

    PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual mac... Read more

    Affected Products : polarssl
    • EPSS Score: %0.43
    • Published: Oct. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2011-4558

    Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.... Read more

    Affected Products : tiki
    • EPSS Score: %3.40
    • Published: Jan. 27, 2020
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2011-4538

    Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.... Read more

    Affected Products : c734_firmware c736_firmware w850_firmware c540 c543 c544 c546 e260 e460 e462 +56 more products
    • EPSS Score: %0.23
    • Published: Mar. 09, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2011-4455

    Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-rename_page.... Read more

    Affected Products : tiki
    • EPSS Score: %0.31
    • Published: Nov. 20, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2011-4454

    Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.... Read more

    Affected Products : tiki
    • EPSS Score: %0.31
    • Published: Nov. 20, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2011-4350

    Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.... Read more

    Affected Products : debian_linux yaws
    • EPSS Score: %25.88
    • Published: Nov. 26, 2019
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2011-4338

    Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.... Read more

    Affected Products : shaman
    • EPSS Score: %0.04
    • Published: Feb. 12, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2011-4336

    Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.... Read more

    Affected Products : tikiwiki_cms\/groupware
    • EPSS Score: %0.93
    • Published: Jan. 15, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2011-4322

    websitebaker prior to and including 2.8.1 has an authentication error in backup module.... Read more

    Affected Products : websitebaker
    • EPSS Score: %0.25
    • Published: Jan. 21, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2011-4310

    The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.... Read more

    Affected Products : cms_made_simple
    • EPSS Score: %0.23
    • Published: Nov. 26, 2019
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2011-4190

    The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remot... Read more

    • EPSS Score: %0.23
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2011-4183

    A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.... Read more

    Affected Products : open_build_service
    • EPSS Score: %0.37
    • Published: Jun. 13, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 291589 Results