Latest CVE Feed
-
6.1
MEDIUMCVE-2012-4440
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.... Read more
Affected Products : jenkins- EPSS Score: %1.50
- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-4439
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.... Read more
Affected Products : jenkins- EPSS Score: %0.44
- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2012-4438
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.... Read more
Affected Products : jenkins- EPSS Score: %1.12
- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2012-4434
fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.... Read more
Affected Products : fwknop- EPSS Score: %5.49
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %46.22
- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-4420
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements righ... Read more
Affected Products : jdk- EPSS Score: %1.07
- Published: Dec. 26, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- EPSS Score: %0.23
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-4384
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar... Read more
- EPSS Score: %0.45
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2012-4383
contao prior to 2.11.4 has a sql injection vulnerability... Read more
Affected Products : contao- EPSS Score: %0.26
- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2012-4381
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a ... Read more
Affected Products : mediawiki- EPSS Score: %4.12
- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-4284
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code... Read more
Affected Products : viscosity- EPSS Score: %49.44
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-4030
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.... Read more
Affected Products : chamilo_lms- EPSS Score: %0.53
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-4029
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.... Read more
Affected Products : chamilo- EPSS Score: %0.53
- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-3824
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.... Read more
Affected Products : campaign_enterprise- EPSS Score: %0.64
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-3823
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.... Read more
Affected Products : campaign_enterprise- EPSS Score: %0.28
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-3822
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.... Read more
Affected Products : campaign_enterprise- EPSS Score: %1.30
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3821
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.... Read more
Affected Products : campaign_enterprise- EPSS Score: %0.39
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-3810
Samsung Kies before 2.5.0.12094_27_11 has registry modification.... Read more
Affected Products : kies- EPSS Score: %25.87
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-3809
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.... Read more
Affected Products : kies- EPSS Score: %25.87
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-3808
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.... Read more
Affected Products : kies- EPSS Score: %25.87
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024