2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-4901 | MEDIUM | 6.5 | 1.1% | Nov 6, 2019 | TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information... |
| CVE-2011-4900 | MEDIUM | 6.5 | 1.0% | Nov 6, 2019 | TYPO3 before 4.5.4 allows Information Disclosure in the backend. |
| CVE-2011-4632 | MEDIUM | 5.4 | 0.7% | Nov 6, 2019 | Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to... |
| CVE-2011-4631 | MEDIUM | 5.4 | 0.7% | Nov 6, 2019 | Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to... |
| CVE-2011-4630 | MEDIUM | 5.4 | 0.7% | Nov 6, 2019 | Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to... |
| CVE-2011-4629 | MEDIUM | 5.4 | 0.7% | Nov 6, 2019 | Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to... |
| CVE-2011-4628 | CRITICAL | 9.8 | 1.6% | Nov 6, 2019 | TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechani... |
| CVE-2011-4627 | MEDIUM | 6.5 | 1.0% | Nov 6, 2019 | TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend. |
| CVE-2011-4626 | MEDIUM | 6.1 | 0.8% | Nov 6, 2019 | Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to... |
| CVE-2011-4625 | HIGH | 7.5 | 0.7% | Nov 6, 2019 | simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote ... |
| CVE-2011-1460 | CRITICAL | 9.8 | 0.9% | Nov 5, 2019 | WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks. |
| CVE-2011-1459 | MEDIUM | 6.5 | 0.7% | Nov 5, 2019 | The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a... |
| CVE-2011-1135 | MEDIUM | 6.1 | 1.8% | Nov 5, 2019 | Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to exe... |
| CVE-2011-1134 | CRITICAL | 9.8 | 3.0% | Nov 5, 2019 | Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to exe... |
| CVE-2011-1133 | MEDIUM | 6.1 | 1.8% | Nov 5, 2019 | Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to exe... |
| CVE-2011-3923 | CRITICAL | 9.8 | 88.8% | Nov 1, 2019 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an... |
| CVE-2011-2186 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2011-1408 | HIGH | 8.2 | 1.6% | Oct 29, 2019 | ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. |
| CVE-2011-4931 | HIGH | 7.5 | 1.5% | Oct 29, 2019 | gpw generates shorter passwords than required |
| CVE-2011-2538 | HIGH | 7.2 | 2.6% | Oct 29, 2019 | Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, au... |
| CVE-2011-0428 | MEDIUM | 6.1 | 0.8% | Oct 29, 2019 | Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due ... |
| CVE-2011-5329 | — | — | 0.9% | Aug 28, 2019 | The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562. |
| CVE-2011-5328 | — | — | 0.7% | Aug 20, 2019 | The user-access-manager plugin before 1.2 for WordPress has CSRF. |
| CVE-2011-5327 | CRITICAL | 9.8 | 3.7% | Jul 27, 2019 | In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function... |
| CVE-2011-3151 | MEDIUM | 5.2 | 0.6% | Apr 22, 2019 | The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If th... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now