Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-7687 |
|
Vulnerability in apache (CVE-2017-7687)
vulnerability in apache (CVE-2017-7687). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8448 |
|
Vulnerability in elastic (CVE-2017-8448)
vulnerability in elastic (CVE-2017-8448). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9790 |
|
Use-After-Free in apache (CVE-2017-9790)
vulnerability in apache (CVE-2017-9790). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12226 |
|
Vulnerability in cisco (CVE-2017-12226)
vulnerability in cisco (CVE-2017-12226). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12230 |
|
Vulnerability in cisco (CVE-2017-12230)
vulnerability in cisco (CVE-2017-12230). Successful exploitation can lead to full system takeover.
|
| CVE-2014-2029 |
|
Information Disclosure in percona (CVE-2014-2029)
vulnerability in percona (CVE-2014-2029). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1483 |
|
Vulnerability in ibm (CVE-2017-1483)
vulnerability in ibm (CVE-2017-1483). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14838 |
|
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
|
| CVE-2017-14839 |
|
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
|
| CVE-2017-14840 |
|
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
|
| CVE-2017-14842 |
|
SQL Injection in wordpress (CVE-2017-14842)
SQL injection in wordpress (CVE-2017-14842). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14843 |
|
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
|
| CVE-2017-14844 |
|
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
|
| CVE-2017-14845 |
|
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
|
| CVE-2017-14846 |
|
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
|
| CVE-2017-14847 |
|
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
|
| CVE-2017-14849 |
|
Path Traversal in nodejs (CVE-2017-14849)
path traversal in nodejs (CVE-2017-14849). Confidential information can be exposed externally.
|
| CVE-2017-1577 |
|
Path Traversal in ibm (CVE-2017-1577)
path traversal in ibm (CVE-2017-1577). Confidential information can be exposed externally.
|
| CVE-2017-2551 |
|
Vulnerability in wordpress (CVE-2017-2551)
vulnerability in wordpress (CVE-2017-2551). Confidential information can be exposed externally.
|
| CVE-2017-11191 |
|
Vulnerability in freeipa (CVE-2017-11191)
vulnerability in freeipa (CVE-2017-11191). Successful exploitation can lead to full system takeover.
|
| CVE-2017-13676 |
|
Code Injection in norton (CVE-2017-13676)
code injection in norton (CVE-2017-13676). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1407 |
|
Command Injection in ibm (CVE-2017-1407)
command injection in ibm (CVE-2017-1407). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14526 |
|
XXE (XML External Entity) in dos (CVE-2017-14526)
vulnerability in dos (CVE-2017-14526). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14527 |
|
XXE (XML External Entity) in dos (CVE-2017-14527)
vulnerability in dos (CVE-2017-14527). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14795 |
|
Out-of-Bounds Read in c (CVE-2017-14795)
vulnerability in c (CVE-2017-14795). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14796 |
|
Vulnerability in c (CVE-2017-14796)
vulnerability in c (CVE-2017-14796). Successful exploitation can lead to full system takeover.
|
| CVE-2015-1336 |
|
Vulnerability in man-db-project (CVE-2015-1336)
vulnerability in man-db-project (CVE-2015-1336). Successful exploitation can lead to full system takeover.
|
| CVE-2015-1537 |
|
Vulnerability in cpp (CVE-2015-1537)
vulnerability in cpp (CVE-2015-1537). Successful exploitation can lead to full system takeover.
|
| CVE-2015-3138 |
|
Vulnerability in c (CVE-2015-3138)
vulnerability in c (CVE-2015-3138). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-3643 |
|
Vulnerability in usb-creator-project (CVE-2015-3643)
vulnerability in usb-creator-project (CVE-2015-3643). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14763 |
|
Vulnerability in genixcms (CVE-2017-14763)
vulnerability in genixcms (CVE-2017-14763). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14764 |
|
Code Injection in genixcms (CVE-2017-14764)
code injection in genixcms (CVE-2017-14764). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14766 |
|
Authentication Bypass in wordpress (CVE-2017-14766)
authentication bypass in wordpress (CVE-2017-14766). Data can be tampered with by attackers.
|
| CVE-2017-14767 |
|
Buffer Overflow in c (CVE-2017-14767)
vulnerability in c (CVE-2017-14767). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14749 |
|
Buffer Overflow in dos (CVE-2017-14749)
vulnerability in dos (CVE-2017-14749). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1527 |
|
XXE (XML External Entity) in ibm (CVE-2017-1527)
vulnerability in ibm (CVE-2017-1527). Confidential information can be exposed externally.
|
| CVE-2017-1539 |
|
Vulnerability in privilege-escalation (CVE-2017-1539)
vulnerability in privilege-escalation (CVE-2017-1539). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14745 |
|
Vulnerability in c (CVE-2017-14745)
vulnerability in c (CVE-2017-14745). Successful exploitation can lead to full system takeover.
|
| CVE-2017-13129 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-13129)
vulnerability in csrf (CVE-2017-13129). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14602 |
|
Authentication Bypass in citrix (CVE-2017-14602)
authentication bypass in citrix (CVE-2017-14602). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14704 |
|
Unrestricted File Upload in laravel (CVE-2017-14704)
vulnerability in laravel (CVE-2017-14704). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5192 |
|
Authentication Bypass in salt (CVE-2017-5192)
authentication bypass in salt (CVE-2017-5192). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2015.8.13, 2016.3.5, 2016.11.2` or later.
|
| CVE-2017-5200 |
|
Vulnerability in salt (CVE-2017-5200)
vulnerability in salt (CVE-2017-5200). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2015.8.13, 2016.3.5, 2016.11.2` or later.
|
| CVE-2017-14743 |
|
SQL Injection in sqli (CVE-2017-14743)
SQL injection in sqli (CVE-2017-14743). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12154 |
|
Vulnerability in c (CVE-2017-12154)
vulnerability in c (CVE-2017-12154). Confidential information can be exposed externally.
|
| CVE-2017-14001 |
|
OS Command Injection in digium (CVE-2017-14001)
OS command injection in digium (CVE-2017-14001). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14739 |
|
Vulnerability in c (CVE-2017-14739)
vulnerability in c (CVE-2017-14739). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9961 |
|
Vulnerability in schneider-electric (CVE-2017-9961)
vulnerability in schneider-electric (CVE-2017-9961). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9962 |
|
Buffer Overflow in aveva (CVE-2017-9962)
vulnerability in aveva (CVE-2017-9962). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-7969 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-7969)
vulnerability in csrf (CVE-2017-7969). Successful exploitation can lead to full system takeover.
|