2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2012-10026CRITICAL10The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability...
CVE-2012-10025CRITICAL10The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnera...
CVE-2012-10021CRITICAL9.3A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 ...
CVE-2012-10020CRITICAL9.8The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up...
CVE-2012-10019CRITICAL9.8The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi...
CVE-2012-6664CRITICAL9.1Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo...
CVE-2012-5872CRITICAL9.8ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php ...
CVE-2012-10011CRITICAL9.8A vulnerability was found in HD FLV PLayer Plugin up to 1.7 on WordPress. It has been rated as critical. Affected by thi...
CVE-2012-10009CRITICAL9.8A vulnerability was found in 404like Plugin up to 1.0.2 on WordPress. It has been classified as critical. Affected is th...
CVE-2012-10008CRITICAL9.8A vulnerability, which was classified as critical, has been found in uakfdotb oneapp. This issue affects some unknown pr...
CVE-2012-10006CRITICAL9.8A vulnerability classified as critical has been found in ale7714 sigeprosi. This affects an unknown part. The manipulati...
CVE-2012-2666CRITICAL9.8golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporar...
CVE-2012-10001CRITICAL9.8The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make ...
CVE-2012-0828CRITICAL9.8Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote ...
CVE-2012-1124CRITICAL9.8SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL...
CVE-2012-6611CRITICAL9.8An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded...
CVE-2012-6306CRITICAL9.8A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file.
CVE-2012-5686CRITICAL9.8ZPanel 10.0.1 has insufficient entropy for its password reset process.
CVE-2012-5618CRITICAL9.8Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
CVE-2012-1495CRITICAL9.8install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user...
CVE-2012-6451CRITICAL9.8Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
CVE-2012-6649CRITICAL9.8WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
CVE-2012-5867CRITICAL9.8HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability
CVE-2012-5699CRITICAL9.8BabyGekko before 1.2.4 allows PHP file inclusion.
CVE-2012-2087CRITICAL9.8ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now