2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6670 | — | — | 1.7% | Jan 11, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vB... |
| CVE-2012-6668 | — | — | 1.7% | Jan 11, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module b... |
| CVE-2012-0699 | — | — | 3.6% | Jan 11, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow re... |
| CVE-2012-6667 | — | — | 4.2% | Jan 11, 2018 | Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows r... |
| CVE-2012-3353 | — | — | 3.1% | Jan 9, 2018 | The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to impo... |
| CVE-2012-2576 | — | — | 59.1% | Dec 20, 2017 | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof... |
| CVE-2012-2456 | — | — | — | Nov 13, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-5174. Reason: This candidate is a reservation ... |
| CVE-2012-5636 | — | — | 3.1% | Oct 30, 2017 | Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0... |
| CVE-2012-4449 | — | — | 1.2% | Oct 30, 2017 | Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when ... |
| CVE-2012-0881 | — | — | 17.1% | Oct 30, 2017 | Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a cr... |
| CVE-2012-5358 | — | — | 1.9% | Oct 30, 2017 | The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with ena... |
| CVE-2012-5357 | — | — | 67.8% | Oct 30, 2017 | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true... |
| CVE-2012-4378 | — | — | 1.5% | Oct 26, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecifie... |
| CVE-2012-4377 | — | — | 1.6% | Oct 26, 2017 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to ... |
| CVE-2012-1622 | — | — | 5.0% | Oct 26, 2017 | Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors. |
| CVE-2012-4570 | — | — | 1.9% | Oct 23, 2017 | SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote... |
| CVE-2012-4569 | — | — | 1.3% | Oct 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow... |
| CVE-2012-4568 | — | — | 1.0% | Oct 23, 2017 | Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attacke... |
| CVE-2012-4567 | — | — | 1.2% | Oct 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to i... |
| CVE-2012-4382 | — | — | 1.2% | Oct 19, 2017 | MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote adm... |
| CVE-2012-4380 | — | — | 1.6% | Oct 19, 2017 | MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address ... |
| CVE-2012-4379 | — | — | 1.4% | Oct 19, 2017 | MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows ... |
| CVE-2012-6707 | — | — | 1.1% | Oct 19, 2017 | WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determi... |
| CVE-2012-6696 | — | — | 1.6% | Sep 25, 2017 | inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of ... |
| CVE-2012-2805 | — | — | 1.9% | Aug 28, 2017 | Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service. |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now