Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2016-4907 |
|
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.
|
| CVE-2016-4909 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2016-4909)
vulnerability in csrf (CVE-2016-4909). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-7809 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2016-7809)
vulnerability in csrf (CVE-2016-7809). Successful exploitation can lead to full system takeover.
|
| CVE-2016-7822 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2016-7822)
vulnerability in csrf (CVE-2016-7822). Successful exploitation can lead to full system takeover.
|
| CVE-2016-7802 |
|
Path Traversal in path-traversal (CVE-2016-7802)
path traversal in path-traversal (CVE-2016-7802). Confidential information can be exposed externally.
|
| CVE-2016-7801 |
|
Vulnerability in dos (CVE-2016-7801)
vulnerability in dos (CVE-2016-7801). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-7820 |
|
Buffer Overflow in dos (CVE-2016-7820)
vulnerability in dos (CVE-2016-7820). Successful exploitation can lead to full system takeover.
|
| CVE-2016-7821 |
|
Vulnerability in dos (CVE-2016-7821)
vulnerability in dos (CVE-2016-7821). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-7469 |
|
Cross-Site Scripting (XSS) in f5 (CVE-2016-7469)
cross-site scripting in f5 (CVE-2016-7469). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9523 |
|
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
|
| CVE-2015-1588 |
|
Cross-Site Scripting (XSS) in open-xchange (CVE-2015-1588)
cross-site scripting in open-xchange (CVE-2015-1588). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-1140 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2017-1140)
cross-site scripting in ibm (CVE-2017-1140). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-1786 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2015-1786)
vulnerability in csrf (CVE-2015-1786). Successful exploitation can lead to full system takeover.
|
| CVE-2015-1379 |
|
Vulnerability in dos (CVE-2015-1379)
vulnerability in dos (CVE-2015-1379). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-3913 |
|
Vulnerability in dos (CVE-2015-3913)
vulnerability in dos (CVE-2015-3913). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-9698 |
|
XXE (XML External Entity) in dos (CVE-2016-9698)
vulnerability in dos (CVE-2016-9698). Confidential information can be exposed externally.
|
| CVE-2014-7919 |
|
Vulnerability in cpp (CVE-2014-7919)
vulnerability in cpp (CVE-2014-7919). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-3091 |
|
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
|
| CVE-2016-2034 |
|
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
|
| CVE-2014-6031 |
|
Buffer Overflow in dos (CVE-2014-6031)
vulnerability in dos (CVE-2014-6031). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-2255 |
|
Vulnerability in dos (CVE-2015-2255)
vulnerability in dos (CVE-2015-2255). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-2800 |
|
Authentication Bypass in dos (CVE-2015-2800)
authentication bypass in dos (CVE-2015-2800). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9022 |
|
Vulnerability in dos (CVE-2017-9022)
vulnerability in dos (CVE-2017-9022). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9023 |
|
Vulnerability in dos (CVE-2017-9023)
vulnerability in dos (CVE-2017-9023). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9310 |
|
Vulnerability in dos (CVE-2017-9310)
vulnerability in dos (CVE-2017-9310). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9330 |
|
Vulnerability in dos (CVE-2017-9330)
vulnerability in dos (CVE-2017-9330). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5878 |
|
Unsafe Deserialization in deserialization (CVE-2017-5878)
vulnerability in deserialization (CVE-2017-5878). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9520 |
|
Use-After-Free in c (CVE-2017-9520)
vulnerability in c (CVE-2017-9520). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9517 |
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
|
| CVE-2017-9518 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-9518)
vulnerability in csrf (CVE-2017-9518). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9519 |
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
|
| CVE-2017-9516 |
|
Cross-Site Scripting (XSS) in craftcms (CVE-2017-9516)
cross-site scripting in craftcms (CVE-2017-9516). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-4908 |
|
Buffer Overflow in dos (CVE-2017-4908)
vulnerability in dos (CVE-2017-4908). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4909 |
|
Buffer Overflow in dos (CVE-2017-4909)
vulnerability in dos (CVE-2017-4909). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4910 |
|
Out-of-Bounds Read in dos (CVE-2017-4910)
vulnerability in dos (CVE-2017-4910). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4911 |
|
Out-of-Bounds Write in dos (CVE-2017-4911)
out-of-bounds write in dos (CVE-2017-4911). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4912 |
|
Out-of-Bounds Read in dos (CVE-2017-4912)
vulnerability in dos (CVE-2017-4912). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4913 |
|
Vulnerability in dos (CVE-2017-4913)
vulnerability in dos (CVE-2017-4913). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6648 |
|
Vulnerability in dos (CVE-2017-6648)
vulnerability in dos (CVE-2017-6648). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-7180 |
|
Vulnerability in privilege-escalation (CVE-2017-7180)
vulnerability in privilege-escalation (CVE-2017-7180). Successful exploitation can lead to full system takeover.
|
| CVE-2015-7346 |
|
SQL injection vulnerability in ZCMS 1.1.
SQL injection vulnerability in ZCMS 1.1.
|
| CVE-2014-9310 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2014-9310)
cross-site scripting in wordpress (CVE-2014-9310). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-6540 |
|
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
|
| CVE-2015-6959 |
|
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
|
| CVE-2015-8235 |
|
Directory traversal vulnerability in Spiffy before 5.4.
Directory traversal vulnerability in Spiffy before 5.4.
|
| CVE-2015-5175 |
|
Vulnerability in apache (CVE-2015-5175)
vulnerability in apache (CVE-2015-5175). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-8538 |
|
dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).
dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).
|
| CVE-2017-9355 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2017-9355)
SSRF in ssrf (CVE-2017-9355). Data can be tampered with by attackers.
|
| CVE-2017-4904 |
|
Buffer Overflow in dos (CVE-2017-4904)
vulnerability in dos (CVE-2017-4904). Successful exploitation can lead to full system takeover.
|
| CVE-2016-0254 |
|
XXE (XML External Entity) in dos (CVE-2016-0254)
vulnerability in dos (CVE-2016-0254). Risk of unauthorized operations or information disclosure.
|