2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-10043CRITICAL9.3A stack-based buffer overflow vulnerability exists in ActFax Server version 4.32, specifically in the "Import Users from...
CVE-2012-10042HIGH8.7Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The appli...
CVE-2012-10041CRITICAL9.3WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec...
CVE-2012-10036CRITICAL9.3Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php....
CVE-2012-10035CRITICAL10Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT comm...
CVE-2012-10034HIGH7.5ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie para...
CVE-2012-10033CRITICAL9.3Narcissus is vulnerable to remote code execution via improper input handling in its image configuration workflow. Specif...
CVE-2012-10032HIGH8.7Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page. ...
CVE-2012-10031HIGH8.6BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supp...
CVE-2012-10030CRITICAL9.8FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbit...
CVE-2012-10029HIGH8.6Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `v...
CVE-2012-10028HIGH8.6Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows auth...
CVE-2012-10027CRITICAL9.3WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerabilit...
CVE-2012-10026CRITICAL10The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability...
CVE-2012-10025CRITICAL10The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnera...
CVE-2012-10024HIGH7.1XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Auth...
CVE-2012-10023CRITICAL9.8A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly v...
CVE-2012-10022HIGH8.5Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege esc...
CVE-2012-10021CRITICAL9.8A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 ...
CVE-2012-10020CRITICAL9.8The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up...
CVE-2012-10019CRITICAL9.8The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi...
CVE-2012-10018HIGH8.3The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and ...
CVE-2012-6664CRITICAL9.1Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo...
CVE-2012-10017HIGH8.8A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic...
CVE-2012-10016HIGH7.5A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPr...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now