Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2012-6720

    Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to... Read more

    Affected Products : socialengine
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-6719

    The sharebar plugin before 1.2.2 for WordPress has SQL injection.... Read more

    Affected Products : sharebar
    • Published: Aug. 28, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6718

    The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.... Read more

    Affected Products : sharebar
    • Published: Aug. 28, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6717

    The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.... Read more

    Affected Products : redirection
    • Published: Aug. 28, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6716

    The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.... Read more

    Affected Products : events_manager events_manager
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6715

    The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.... Read more

    Affected Products : formbuilder
    • Published: Aug. 21, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6714

    The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.... Read more

    Affected Products : count_per_day
    • Published: Aug. 21, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6713

    The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.... Read more

    Affected Products : job_manager
    • Published: Aug. 13, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-6712

    In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.... Read more

    Affected Products : linux_kernel
    • Published: Jul. 27, 2019
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2012-6711

    A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print ... Read more

    Affected Products : bash enterprise_linux
    • Published: Jun. 18, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-6710

    ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.... Read more

    Affected Products : extplorer
    • Published: Oct. 07, 2018
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2012-6709

    ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.... Read more

    Affected Products : links elinks
    • Published: Feb. 23, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6708

    jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for th... Read more

    Affected Products : jquery
    • Published: Jan. 18, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-6685

    Nokogiri before 1.5.4 is vulnerable to XXE attacks... Read more

    • Published: Feb. 19, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6682

    Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter.... Read more

    Affected Products : vbdownloads_module
    • Published: Jan. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6671

    Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attackers to inject arbitrary web script or HTML via the (1) mon... Read more

    Affected Products : forumon_rpg_module
    • Published: Jan. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6670

    Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the reason parameter in (1) actions/nominatemedal.php or (2) ... Read more

    Affected Products : vbactivity_module
    • Published: Jan. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6668

    Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the (1) reportreason parameter in actions/d... Read more

    Affected Products : vbshout_module
    • Published: Jan. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6667

    Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.... Read more

    Affected Products : vbshout
    • Published: Jan. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6666

    vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.... Read more

    Affected Products : vbseo
    • Published: Feb. 10, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 293343 Results