2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-4901MEDIUM6.5TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information...
CVE-2011-4900MEDIUM6.5TYPO3 before 4.5.4 allows Information Disclosure in the backend.
CVE-2011-4632MEDIUM5.4Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to...
CVE-2011-4631MEDIUM5.4Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to...
CVE-2011-4630MEDIUM5.4Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to...
CVE-2011-4629MEDIUM5.4Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to...
CVE-2011-4628CRITICAL9.8TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechani...
CVE-2011-4627MEDIUM6.5TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.
CVE-2011-4626MEDIUM6.1Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to...
CVE-2011-4625HIGH7.5simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote ...
CVE-2011-1460CRITICAL9.8WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
CVE-2011-1459MEDIUM6.5The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a...
CVE-2011-1135MEDIUM6.1Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to exe...
CVE-2011-1134CRITICAL9.8Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to exe...
CVE-2011-1133MEDIUM6.1Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to exe...
CVE-2011-3923CRITICAL9.8Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an...
CVE-2011-2186Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2011-1408HIGH8.2ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
CVE-2011-4931HIGH7.5gpw generates shorter passwords than required
CVE-2011-2538HIGH7.2Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, au...
CVE-2011-0428MEDIUM6.1Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due ...
CVE-2011-5329The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.
CVE-2011-5328The user-access-manager plugin before 1.2 for WordPress has CSRF.
CVE-2011-5327CRITICAL9.8In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function...
CVE-2011-3151MEDIUM5.2The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If th...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now