Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.2

    HIGH
    CVE-2012-1168

    Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.... Read more

    Affected Products : moodle enterprise_linux fedora
    • EPSS Score: %2.22
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2012-1161

    Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results... Read more

    Affected Products : moodle fedora
    • EPSS Score: %0.95
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 4.0

    MEDIUM
    CVE-2012-1160

    Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php... Read more

    Affected Products : moodle fedora
    • EPSS Score: %0.75
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2012-1159

    Moodle before 2.2.2: Overview report allows users to see hidden courses... Read more

    Affected Products : moodle fedora
    • EPSS Score: %0.95
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2012-1158

    Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export... Read more

    Affected Products : moodle fedora
    • EPSS Score: %0.95
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2012-1157

    Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default... Read more

    Affected Products : moodle fedora
    • EPSS Score: %0.58
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-1156

    Moodle before 2.2.2 has users' private files included in course backups... Read more

    Affected Products : moodle enterprise_linux fedora
    • EPSS Score: %1.23
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-1155

    Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to... Read more

    • EPSS Score: %1.27
    • Published: Nov. 14, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-1124

    SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.... Read more

    Affected Products : phxeventmanager
    • EPSS Score: %2.92
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-1115

    A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.... Read more

    • EPSS Score: %0.84
    • Published: Dec. 05, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-1114

    A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.... Read more

    • EPSS Score: %0.84
    • Published: Dec. 05, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-1109

    mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions... Read more

    Affected Products : mwlib
    • EPSS Score: %0.68
    • Published: Nov. 12, 2019
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2012-1105

    An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.... Read more

    Affected Products : fedora debian_linux phpcas
    • EPSS Score: %0.15
    • Published: Dec. 05, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2012-1104

    A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.... Read more

    Affected Products : linux_kernel debian_linux phpcas
    • EPSS Score: %0.24
    • Published: Dec. 05, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-1102

    It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the... Read more

    Affected Products : \
    • EPSS Score: %0.29
    • Published: Jul. 09, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2012-1101

    systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure).... Read more

    Affected Products : systemd
    • EPSS Score: %0.15
    • Published: Mar. 11, 2020
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2012-1096

    NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.... Read more

    Affected Products : debian_linux networkmanager
    • EPSS Score: %0.35
    • Published: Mar. 10, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-1094

    JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.... Read more

    • EPSS Score: %0.24
    • Published: Mar. 10, 2020
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2012-1093

    The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.... Read more

    Affected Products : debian_linux x11-common
    • EPSS Score: %0.14
    • Published: Feb. 21, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-1001

    Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php.... Read more

    Affected Products : chyrp
    • EPSS Score: %19.24
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 291712 Results