Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2017-17091 Vulnerability in wordpress (CVE-2017-17091)
vulnerability in wordpress (CVE-2017-17091). Successful exploitation can lead to full system takeover.
CVE-2017-15701 Vulnerability in c (CVE-2017-15701)
vulnerability in c (CVE-2017-15701). Risk of unauthorized operations or information disclosure.
CVE-2017-12631 Cross-Site Request Forgery (CSRF) in apache (CVE-2017-12631)
vulnerability in apache (CVE-2017-12631). Successful exploitation can lead to full system takeover.
CVE-2017-17058 Path Traversal in wordpress (CVE-2017-17058)
path traversal in wordpress (CVE-2017-17058). Confidential information can be exposed externally.
CVE-2017-16955 SQL Injection in wordpress (CVE-2017-16955)
SQL injection in wordpress (CVE-2017-16955). Successful exploitation can lead to full system takeover.
CVE-2017-12608 Out-of-Bounds Write in apache (CVE-2017-12608)
out-of-bounds write in apache (CVE-2017-12608). Successful exploitation can lead to full system takeover.
CVE-2017-12607 Out-of-Bounds Write in dos (CVE-2017-12607)
out-of-bounds write in dos (CVE-2017-12607). Successful exploitation can lead to full system takeover.
CVE-2017-9806 Out-of-Bounds Write in dos (CVE-2017-9806)
out-of-bounds write in dos (CVE-2017-9806). Successful exploitation can lead to full system takeover.
CVE-2016-6804 Vulnerability in apache (CVE-2016-6804)
vulnerability in apache (CVE-2016-6804). Successful exploitation can lead to full system takeover.
CVE-2017-16894 Information Disclosure in laravel (CVE-2017-16894)
vulnerability in laravel (CVE-2017-16894). Confidential information can be exposed externally.
CVE-2017-16877 Path Traversal in path-traversal (CVE-2017-16877)
path traversal in path-traversal (CVE-2017-16877). Confidential information can be exposed externally.
CVE-2017-16870 SSRF (Server-Side Request Forgery) in wordpress (CVE-2017-16870)
SSRF in wordpress (CVE-2017-16870). Successful exploitation can lead to full system takeover.
CVE-2017-16871 Code Injection in wordpress (CVE-2017-16871)
code injection in wordpress (CVE-2017-16871). Successful exploitation can lead to full system takeover.
CVE-2017-1000247 Vulnerability in apache (CVE-2017-1000247)
vulnerability in apache (CVE-2017-1000247). Data can be tampered with by attackers.
CVE-2017-12636 OS Command Injection in apache (CVE-2017-12636)
OS command injection in apache (CVE-2017-12636). Successful exploitation can lead to full system takeover.
CVE-2016-6803 Vulnerability in apache (CVE-2016-6803)
vulnerability in apache (CVE-2016-6803). Successful exploitation can lead to full system takeover.
CVE-2017-3166 Vulnerability in apache (CVE-2017-3166)
vulnerability in apache (CVE-2017-3166). Successful exploitation can lead to full system takeover.
CVE-2017-12261 Vulnerability in express (CVE-2017-12261)
vulnerability in express (CVE-2017-12261). Successful exploitation can lead to full system takeover.
CVE-2014-0072 Vulnerability in apache (CVE-2014-0072)
vulnerability in apache (CVE-2014-0072). Data can be tampered with by attackers.
CVE-2012-0881 Vulnerability in apache (CVE-2012-0881)
vulnerability in apache (CVE-2012-0881). Risk of unauthorized operations or information disclosure.
CVE-2014-0115 Path Traversal in apache (CVE-2014-0115)
path traversal in apache (CVE-2014-0115). Confidential information can be exposed externally.
CVE-2016-3090 Vulnerability in apache (CVE-2016-3090)
vulnerability in apache (CVE-2016-3090). Successful exploitation can lead to full system takeover.
CVE-2013-4246 Vulnerability in c (CVE-2013-4246)
vulnerability in c (CVE-2013-4246). Successful exploitation can lead to full system takeover.
CVE-2014-3526 Information Disclosure in apache (CVE-2014-3526)
vulnerability in apache (CVE-2014-3526). Confidential information can be exposed externally.
CVE-2015-0224 Vulnerability in apache (CVE-2015-0224)
vulnerability in apache (CVE-2015-0224). Risk of unauthorized operations or information disclosure.
CVE-2015-0226 Vulnerability in apache (CVE-2015-0226)
vulnerability in apache (CVE-2015-0226). Confidential information can be exposed externally.
CVE-2016-5002 XXE (XML External Entity) in apache (CVE-2016-5002)
vulnerability in apache (CVE-2016-5002). Successful exploitation can lead to full system takeover.
CVE-2017-12613 Out-of-Bounds Read in apache (CVE-2017-12613)
vulnerability in apache (CVE-2017-12613). Confidential information can be exposed externally.
CVE-2015-5533 SQL Injection in wordpress (CVE-2015-5533)
SQL injection in wordpress (CVE-2015-5533). Successful exploitation can lead to full system takeover.
CVE-2010-2232 Vulnerability in apache (CVE-2010-2232)
vulnerability in apache (CVE-2010-2232). Data can be tampered with by attackers.
CVE-2017-12628 Unsafe Deserialization in apache (CVE-2017-12628)
vulnerability in apache (CVE-2017-12628). Successful exploitation can lead to full system takeover.
CVE-2015-6668 Information Disclosure in wordpress (CVE-2015-6668)
vulnerability in wordpress (CVE-2015-6668). Confidential information can be exposed externally.
CVE-2017-5635 Authentication Bypass in apache (CVE-2017-5635)
authentication bypass in apache (CVE-2017-5635). Confidential information can be exposed externally.
CVE-2012-6707 Vulnerability in wordpress (CVE-2012-6707)
vulnerability in wordpress (CVE-2012-6707). Confidential information can be exposed externally.
CVE-2015-5227 Vulnerability in wordpress (CVE-2015-5227)
vulnerability in wordpress (CVE-2015-5227). Successful exploitation can lead to full system takeover.
CVE-2016-4461 Vulnerability in apache (CVE-2016-4461)
vulnerability in apache (CVE-2016-4461). Successful exploitation can lead to full system takeover.
CVE-2017-10619 Vulnerability in express (CVE-2017-10619)
vulnerability in express (CVE-2017-10619). Risk of unauthorized operations or information disclosure.
CVE-2017-5637 Vulnerability in apache (CVE-2017-5637)
vulnerability in apache (CVE-2017-5637). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.10` or later.
CVE-2015-2673 Vulnerability in wordpress (CVE-2015-2673)
vulnerability in wordpress (CVE-2015-2673). Successful exploitation can lead to full system takeover.
CVE-2017-15079 Path Traversal in wordpress (CVE-2017-15079)
path traversal in wordpress (CVE-2017-15079). Confidential information can be exposed externally.
CVE-2017-14848 SQL Injection in wordpress (CVE-2017-14848)
SQL injection in wordpress (CVE-2017-14848). Successful exploitation can lead to full system takeover.
CVE-2016-6806 Cross-Site Request Forgery (CSRF) in apache (CVE-2016-6806)
vulnerability in apache (CVE-2016-6806). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
CVE-2017-13989 Vulnerability in express (CVE-2017-13989)
vulnerability in express (CVE-2017-13989). Confidential information can be exposed externally.
CVE-2015-9233 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2015-9233)
vulnerability in wordpress (CVE-2015-9233). Successful exploitation can lead to full system takeover.
CVE-2015-9234 SQL Injection in wordpress (CVE-2015-9234)
SQL injection in wordpress (CVE-2015-9234). Successful exploitation can lead to full system takeover.
CVE-2016-4434 XXE (XML External Entity) in apache (CVE-2016-4434)
vulnerability in apache (CVE-2016-4434). Successful exploitation can lead to full system takeover.
CVE-2017-7687 Vulnerability in apache (CVE-2017-7687)
vulnerability in apache (CVE-2017-7687). Risk of unauthorized operations or information disclosure.
CVE-2017-9790 Use-After-Free in apache (CVE-2017-9790)
vulnerability in apache (CVE-2017-9790). Risk of unauthorized operations or information disclosure.
CVE-2017-14842 SQL Injection in wordpress (CVE-2017-14842)
SQL injection in wordpress (CVE-2017-14842). Successful exploitation can lead to full system takeover.
CVE-2017-14843 Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →