Latest CVE Feed
-
8.8
HIGHCVE-2011-5328
The user-access-manager plugin before 1.2 for WordPress has CSRF.... Read more
Affected Products : user_access_manager- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-5327
In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.... Read more
Affected Products : linux_kernel- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2011-5282
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.... Read more
Affected Products : mirc- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-5271
Pacemaker before 1.1.6 configure script creates temporary files insecurely... Read more
Affected Products : pacemaker- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-5266
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.... Read more
Affected Products : securesphere_web_application_firewall- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2011-5250
Snare for Linux before 1.7.0 has CSRF in the web interface.... Read more
Affected Products : snare- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-5247
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.... Read more
Affected Products : snare- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-5020
An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.... Read more
Affected Products : online_tv_database- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-5018
Koala Framework before 2011-11-21 has XSS via the request_uri parameter.... Read more
Affected Products : koala_framework- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4973
Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and entering 'password' as the password.... Read more
Affected Products : mod_nss- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-4972
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.... Read more
Affected Products : ckeditor- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2011-4968
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)... Read more
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2011-4954
cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE... Read more
Affected Products : cobbler- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2011-4952
cobbler: Web interface lacks CSRF protection when using Django framework... Read more
Affected Products : cobbler- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4943
ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)... Read more
Affected Products : impresspages_cms- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-4938
Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) index.php and (2) loader.php.... Read more
Affected Products : ariadne- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-4937
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.... Read more
Affected Products : joomla\!- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGH- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-4924
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vecto... Read more
Affected Products : zope- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024