Core Security
131 exploits
Active since Mar 2003
Artweaver < 3.1.6 - Buffer Overflow via Crafted AWD File
W3C Amaya < 11.0 - Remote Code Execution via Long Input Tag Type Parameter
WordPress < 2.8.1 - Unauthenticated Sensitive Information Exposure via Plugin Configuration
vBulletin <3.7.2 PL1, <3.6.10 PL3 - XSS
TestLink - Authenticated SQL Injection via Test Case ID or logLevel Parameter
SoftNAS Cloud <4.0.3 - Command Injection
CVSS 9.8
ZOHO ManageEngine ADSelfService Plus <4.5.4500 - XSS
ZOHO ManageEngine ADSelfService Plus <4.5 Build 4500 - RCE
D-Link Central WiFi Manager <1.03r0100-Beta1 - XSS
CVSS 6.1
IBM WebSphere Application Server <7.0.0.13 - CSRF
Mac OS X <= 10.6.8 - Remote Code Execution in Directory Service
CubeCart 4.3.4-4.3.9 - SQL Injection via shipKey Parameter
RealNetworks Helix Server <13.0.0 - DoS
Blender 2.34, 2.35a, 2.40, 2.49b - Remote Code Execution via ScriptLink SDNA onLoad Action
Sun xVM VirtualBox <1.6.4 - Privilege Escalation
CVSS 8.8
Sun Calendar Express Web Server - Denial of Service / Cross-Site Scripting
SAP NetWeaver 7.0 EHP1 and EHP2 - Denial of Service via Crafted SAP Diag Packet
Oracle VirtualBox < 4.3.8 Local Guest-to-Host RCE via 3D Acceleration
Sophos Web Appliance <3.7.9.1, <3.8-3.8.1.1 - Privilege Escalation
Kaspersky Anti-Virus for Linux File Server <8.0.4.312 - XSS
CVSS 6.1
Ximian Evolution Mail User Agent <= 1.2.2 - Denial of Service via Uuencoded Mail Message
Dell EMC Isilon OneFS CSRF (7.1.1.11, 7.2.1.0-7.2.1.5, 8.0.0.0-8.0.0.6, 8.0.1.0-8.0.1.2, 8.1.0.0-8.1.0.2)
CVSS 8.8
Ximian Evolution Mail User Agent <1.2.2 - XSS
PineApp Mail-SeCure <3.70 - Privilege Escalation
Eye Of Gnome - Remote Code Execution via Format String Specifiers in Command Line Argument