Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-17091 |
|
Vulnerability in wordpress (CVE-2017-17091)
vulnerability in wordpress (CVE-2017-17091). Successful exploitation can lead to full system takeover.
|
| CVE-2017-15701 |
|
Vulnerability in c (CVE-2017-15701)
vulnerability in c (CVE-2017-15701). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12631 |
|
Cross-Site Request Forgery (CSRF) in apache (CVE-2017-12631)
vulnerability in apache (CVE-2017-12631). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17058 |
|
Path Traversal in wordpress (CVE-2017-17058)
path traversal in wordpress (CVE-2017-17058). Confidential information can be exposed externally.
|
| CVE-2017-16955 |
|
SQL Injection in wordpress (CVE-2017-16955)
SQL injection in wordpress (CVE-2017-16955). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12608 |
|
Out-of-Bounds Write in apache (CVE-2017-12608)
out-of-bounds write in apache (CVE-2017-12608). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12607 |
|
Out-of-Bounds Write in dos (CVE-2017-12607)
out-of-bounds write in dos (CVE-2017-12607). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9806 |
|
Out-of-Bounds Write in dos (CVE-2017-9806)
out-of-bounds write in dos (CVE-2017-9806). Successful exploitation can lead to full system takeover.
|
| CVE-2016-6804 |
|
Vulnerability in apache (CVE-2016-6804)
vulnerability in apache (CVE-2016-6804). Successful exploitation can lead to full system takeover.
|
| CVE-2017-16894 |
|
Information Disclosure in laravel (CVE-2017-16894)
vulnerability in laravel (CVE-2017-16894). Confidential information can be exposed externally.
|
| CVE-2017-16877 |
|
Path Traversal in path-traversal (CVE-2017-16877)
path traversal in path-traversal (CVE-2017-16877). Confidential information can be exposed externally.
|
| CVE-2017-16870 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2017-16870)
SSRF in wordpress (CVE-2017-16870). Successful exploitation can lead to full system takeover.
|
| CVE-2017-16871 |
|
Code Injection in wordpress (CVE-2017-16871)
code injection in wordpress (CVE-2017-16871). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000247 |
|
Vulnerability in apache (CVE-2017-1000247)
vulnerability in apache (CVE-2017-1000247). Data can be tampered with by attackers.
|
| CVE-2017-12636 |
|
OS Command Injection in apache (CVE-2017-12636)
OS command injection in apache (CVE-2017-12636). Successful exploitation can lead to full system takeover.
|
| CVE-2016-6803 |
|
Vulnerability in apache (CVE-2016-6803)
vulnerability in apache (CVE-2016-6803). Successful exploitation can lead to full system takeover.
|
| CVE-2017-3166 |
|
Vulnerability in apache (CVE-2017-3166)
vulnerability in apache (CVE-2017-3166). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12261 |
|
Vulnerability in express (CVE-2017-12261)
vulnerability in express (CVE-2017-12261). Successful exploitation can lead to full system takeover.
|
| CVE-2014-0072 |
|
Vulnerability in apache (CVE-2014-0072)
vulnerability in apache (CVE-2014-0072). Data can be tampered with by attackers.
|
| CVE-2012-0881 |
|
Vulnerability in apache (CVE-2012-0881)
vulnerability in apache (CVE-2012-0881). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-0115 |
|
Path Traversal in apache (CVE-2014-0115)
path traversal in apache (CVE-2014-0115). Confidential information can be exposed externally.
|
| CVE-2016-3090 |
|
Vulnerability in apache (CVE-2016-3090)
vulnerability in apache (CVE-2016-3090). Successful exploitation can lead to full system takeover.
|
| CVE-2013-4246 |
|
Vulnerability in c (CVE-2013-4246)
vulnerability in c (CVE-2013-4246). Successful exploitation can lead to full system takeover.
|
| CVE-2014-3526 |
|
Information Disclosure in apache (CVE-2014-3526)
vulnerability in apache (CVE-2014-3526). Confidential information can be exposed externally.
|
| CVE-2015-0224 |
|
Vulnerability in apache (CVE-2015-0224)
vulnerability in apache (CVE-2015-0224). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-0226 |
|
Vulnerability in apache (CVE-2015-0226)
vulnerability in apache (CVE-2015-0226). Confidential information can be exposed externally.
|
| CVE-2016-5002 |
|
XXE (XML External Entity) in apache (CVE-2016-5002)
vulnerability in apache (CVE-2016-5002). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12613 |
|
Out-of-Bounds Read in apache (CVE-2017-12613)
vulnerability in apache (CVE-2017-12613). Confidential information can be exposed externally.
|
| CVE-2015-5533 |
|
SQL Injection in wordpress (CVE-2015-5533)
SQL injection in wordpress (CVE-2015-5533). Successful exploitation can lead to full system takeover.
|
| CVE-2010-2232 |
|
Vulnerability in apache (CVE-2010-2232)
vulnerability in apache (CVE-2010-2232). Data can be tampered with by attackers.
|
| CVE-2017-12628 |
|
Unsafe Deserialization in apache (CVE-2017-12628)
vulnerability in apache (CVE-2017-12628). Successful exploitation can lead to full system takeover.
|
| CVE-2015-6668 |
|
Information Disclosure in wordpress (CVE-2015-6668)
vulnerability in wordpress (CVE-2015-6668). Confidential information can be exposed externally.
|
| CVE-2017-5635 |
|
Authentication Bypass in apache (CVE-2017-5635)
authentication bypass in apache (CVE-2017-5635). Confidential information can be exposed externally.
|
| CVE-2012-6707 |
|
Vulnerability in wordpress (CVE-2012-6707)
vulnerability in wordpress (CVE-2012-6707). Confidential information can be exposed externally.
|
| CVE-2015-5227 |
|
Vulnerability in wordpress (CVE-2015-5227)
vulnerability in wordpress (CVE-2015-5227). Successful exploitation can lead to full system takeover.
|
| CVE-2016-4461 |
|
Vulnerability in apache (CVE-2016-4461)
vulnerability in apache (CVE-2016-4461). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10619 |
|
Vulnerability in express (CVE-2017-10619)
vulnerability in express (CVE-2017-10619). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5637 |
|
Vulnerability in apache (CVE-2017-5637)
vulnerability in apache (CVE-2017-5637). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.10` or later.
|
| CVE-2015-2673 |
|
Vulnerability in wordpress (CVE-2015-2673)
vulnerability in wordpress (CVE-2015-2673). Successful exploitation can lead to full system takeover.
|
| CVE-2017-15079 |
|
Path Traversal in wordpress (CVE-2017-15079)
path traversal in wordpress (CVE-2017-15079). Confidential information can be exposed externally.
|
| CVE-2017-14848 |
|
SQL Injection in wordpress (CVE-2017-14848)
SQL injection in wordpress (CVE-2017-14848). Successful exploitation can lead to full system takeover.
|
| CVE-2016-6806 |
|
Cross-Site Request Forgery (CSRF) in apache (CVE-2016-6806)
vulnerability in apache (CVE-2016-6806). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2017-13989 |
|
Vulnerability in express (CVE-2017-13989)
vulnerability in express (CVE-2017-13989). Confidential information can be exposed externally.
|
| CVE-2015-9233 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2015-9233)
vulnerability in wordpress (CVE-2015-9233). Successful exploitation can lead to full system takeover.
|
| CVE-2015-9234 |
|
SQL Injection in wordpress (CVE-2015-9234)
SQL injection in wordpress (CVE-2015-9234). Successful exploitation can lead to full system takeover.
|
| CVE-2016-4434 |
|
XXE (XML External Entity) in apache (CVE-2016-4434)
vulnerability in apache (CVE-2016-4434). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7687 |
|
Vulnerability in apache (CVE-2017-7687)
vulnerability in apache (CVE-2017-7687). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9790 |
|
Use-After-Free in apache (CVE-2017-9790)
vulnerability in apache (CVE-2017-9790). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14842 |
|
SQL Injection in wordpress (CVE-2017-14842)
SQL injection in wordpress (CVE-2017-14842). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14843 |
|
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
|