|
291221
|
7.5 |
HIGH
Network
|
sillycycle fedoraproject
|
xlockmore fedora
|
xlockmore before 5.43 'dclock' security bypass vulnerability
|
CWE-20
Improper Input Validation
|
CVE-2012-4524
|
2024-11-21 10:43 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291222
|
9.8 |
CRITICAL
Network
|
letodms_project
|
letodms
|
SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-4570
|
2024-11-21 10:43 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291223
|
6.1 |
MEDIUM
Network
|
letodms_project
|
letodms
|
Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vector…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4569
|
2024-11-21 10:43 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291224
|
8.8 |
HIGH
Network
|
letodms_project
|
letodms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2012-4568
|
2024-11-21 10:43 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291225
|
6.1 |
MEDIUM
Network
|
letodms_project
|
letodms
|
Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) inc/inc.Cl…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4567
|
2024-11-21 10:43 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291226
|
6.5 |
MEDIUM
Network
|
cisco
|
ios
|
Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote authenticated users to cause a denial of service (CPU consumption, watchdog timeout, crash) by walking…
|
CWE-399
Resource Management Errors
|
CVE-2012-5030
|
2024-11-21 10:43 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291227
|
8.1 |
HIGH
Adjacent
|
cisco
|
adaptive_security_appliance_software
|
ASA 5515-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x before 9.2.4 Interim, ASA 5510 Adaptive Security Appliance Adaptive Security Applia…
|
CWE-254
7PK - Security Features
|
CVE-2012-5010
|
2024-11-21 10:43 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291228
|
- |
|
n-tron
|
702w_industrial_wireless_access_point
|
N-Tron 702-W Industrial Wireless Access Point devices use the same (1) SSH and (2) HTTPS private keys across different customers' installations, which makes it easier for remote attackers to defeat c…
|
CWE-310
Cryptographic Issues
|
CVE-2012-4716
|
2024-11-21 10:43 |
2015-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291229
|
- |
|
template_cms_project
|
template_cms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create an admi…
|
CWE-352
Origin Validation Error
|
CVE-2012-4902
|
2024-11-21 10:43 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291230
|
- |
|
template_cms_project
|
template_cms
|
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to …
|
CWE-79
Cross-site Scripting
|
CVE-2012-4901
|
2024-11-21 10:43 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|