2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-3473 | — | — | 2.3% | Aug 12, 2012 | The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not requir... |
| CVE-2012-3472 | — | — | 1.3% | Aug 12, 2012 | The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require ... |
| CVE-2012-3471 | — | — | 1.8% | Aug 12, 2012 | Multiple SQL injection vulnerabilities in the edit functions in (1) application/controllers/admin/reports.php and (2) ap... |
| CVE-2012-3470 | — | — | 1.2% | Aug 12, 2012 | Multiple SQL injection vulnerabilities in application/libraries/api/MY_Countries_Api_Object.php in the Ushahidi Platform... |
| CVE-2012-3469 | — | — | 1.3% | Aug 12, 2012 | Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary S... |
| CVE-2012-3468 | — | — | 1.3% | Aug 12, 2012 | Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary S... |
| CVE-2012-2590 | — | — | 1.3% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attacke... |
| CVE-2012-2587 | — | — | 1.3% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arb... |
| CVE-2012-2585 | — | — | 1.4% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to injec... |
| CVE-2012-2573 | — | — | 1.3% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail 3.2.0-2.3 allow remote attackers to inject arbitrar... |
| CVE-2012-2571 | — | — | 1.3% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitr... |
| CVE-2012-4249 | — | — | 3.7% | Aug 12, 2012 | The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent a... |
| CVE-2012-4248 | — | — | 3.5% | Aug 12, 2012 | The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface,... |
| CVE-2012-4070 | — | — | 1.0% | Aug 12, 2012 | SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL... |
| CVE-2012-4069 | — | — | 1.2% | Aug 12, 2012 | Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attack... |
| CVE-2012-2584 | — | — | 3.2% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitr... |
| CVE-2012-2969 | — | — | 3.5% | Aug 12, 2012 | Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filena... |
| CVE-2012-2968 | — | — | 3.5% | Aug 12, 2012 | Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to c... |
| CVE-2012-2967 | — | — | 1.6% | Aug 12, 2012 | Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) oper... |
| CVE-2012-2966 | — | — | 1.6% | Aug 12, 2012 | Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis o... |
| CVE-2012-2965 | — | — | 1.6% | Aug 12, 2012 | Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of v... |
| CVE-2012-2964 | — | — | 1.8% | Aug 12, 2012 | The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI admini... |
| CVE-2012-2963 | — | — | 1.8% | Aug 12, 2012 | The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require... |
| CVE-2012-2602 | — | — | 6.0% | Aug 12, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before ... |
| CVE-2012-2577 | — | — | 10.2% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 ... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now