2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-3473The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not requir...
CVE-2012-3472The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require ...
CVE-2012-3471Multiple SQL injection vulnerabilities in the edit functions in (1) application/controllers/admin/reports.php and (2) ap...
CVE-2012-3470Multiple SQL injection vulnerabilities in application/libraries/api/MY_Countries_Api_Object.php in the Ushahidi Platform...
CVE-2012-3469Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary S...
CVE-2012-3468Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary S...
CVE-2012-2590Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attacke...
CVE-2012-2587Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arb...
CVE-2012-2585Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to injec...
CVE-2012-2573Multiple cross-site scripting (XSS) vulnerabilities in T-dah WebMail 3.2.0-2.3 allow remote attackers to inject arbitrar...
CVE-2012-2571Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitr...
CVE-2012-4249The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent a...
CVE-2012-4248The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface,...
CVE-2012-4070SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL...
CVE-2012-4069Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attack...
CVE-2012-2584Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitr...
CVE-2012-2969Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filena...
CVE-2012-2968Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to c...
CVE-2012-2967Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) oper...
CVE-2012-2966Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis o...
CVE-2012-2965Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of v...
CVE-2012-2964The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI admini...
CVE-2012-2963The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require...
CVE-2012-2602Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before ...
CVE-2012-2577Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now