2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-4682——The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers t...
CVE-2011-4681——Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names...
CVE-2011-4680——Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM before 5.2.0 allow remote attac...
CVE-2011-4679——vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows rem...
CVE-2011-4263——Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote atta...
CVE-2011-2462CRITICAL9.8Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, a...
CVE-2011-4678——The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts d...
CVE-2011-4677——One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier...
CVE-2011-4555——One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticate...
CVE-2011-4554——One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) a...
CVE-2011-4553——Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to ar...
CVE-2011-4552——Multiple cross-site scripting (XSS) vulnerabilities in One Click Orgs before 1.2.3 allow remote attackers to inject arbi...
CVE-2011-4130——Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute a...
CVE-2011-4675——The pathname canonicalization functionality in io/filesystem/filesystem.cc in Widelands before 15.1 expands leading ~ (t...
CVE-2011-4543——Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary...
CVE-2011-4356——Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id dur...
CVE-2011-4162——The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless me...
CVE-2011-4052——Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio ...
CVE-2011-4051——CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require au...
CVE-2011-2397——The Agent service in Iron Mountain Connected Backup 8.4 allows remote attackers to execute arbitrary code via a crafted ...
CVE-2011-1932——Directory traversal vulnerability in io/filesystem/filesystem.cc in Widelands before 15.1 might allow remote attackers t...
CVE-2011-4674——SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows rem...
CVE-2011-4673——SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to exe...
CVE-2011-4672——Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL...
CVE-2011-4671——SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, ...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now