2011 CVE Vulnerabilities

4,898 CVEs published in 2011.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2011-1151CRITICAL9.1Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
CVE-2011-3621CRITICAL9.8A reverse proxy issue exists in FluxBB before 1.4.7 when FORUM_BEHIND_REVERSE_PROXY is enabled.
CVE-2011-3614CRITICAL9.8An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.
CVE-2011-4943CRITICAL9.8ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)
CVE-2011-4094CRITICAL9.8Jara 1.6 has a SQL injection vulnerability.
CVE-2011-2715CRITICAL9.8An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table...
CVE-2011-3203CRITICAL9.8A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.
CVE-2011-5020CRITICAL9.8An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.
CVE-2011-5266CRITICAL9.8Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
CVE-2011-2717CRITICAL9.8The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitr...
CVE-2011-2523CRITICAL9.8vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
CVE-2011-1939CRITICAL9.8SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compati...
CVE-2011-1933CRITICAL9.8SQL injection vulnerability in Jifty::DBI before 0.68.
CVE-2011-4121CRITICAL9.8The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value ...
CVE-2011-4120CRITICAL9.8Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used ...
CVE-2011-3584CRITICAL9.8The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-s...
CVE-2011-3583CRITICAL9.8It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not prope...
CVE-2011-1028CRITICAL9.8The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smar...
CVE-2011-3350CRITICAL9.8masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privi...
CVE-2011-2921CRITICAL9.8ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com...
CVE-2011-5331CRITICAL9.8Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.
CVE-2011-5330CRITICAL9.8Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.
CVE-2011-0703CRITICAL9.8In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to over...
CVE-2011-1930CRITICAL9.8In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This...
CVE-2011-2936CRITICAL9.8Elgg through 1.7.10 has a SQL injection vulnerability

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now