2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5556 | — | — | 0.6% | Dec 3, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.... |
| CVE-2012-5554 | — | — | 1.4% | Dec 3, 2012 | The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" di... |
| CVE-2012-5553 | — | — | 0.9% | Dec 3, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu module 6.x-1.x before 6.x-1.44 and 7.x-1.x before... |
| CVE-2012-5552 | — | — | 1.4% | Dec 3, 2012 | The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtai... |
| CVE-2012-5551 | — | — | 1.2% | Dec 3, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remo... |
| CVE-2012-5550 | — | — | 1.1% | Dec 3, 2012 | SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary... |
| CVE-2012-5549 | — | — | 0.6% | Dec 3, 2012 | Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers ... |
| CVE-2012-5548 | — | — | 0.9% | Dec 3, 2012 | Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to inje... |
| CVE-2012-5547 | — | — | 0.6% | Dec 3, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Search API module 7.x-1.x before 7.x-1.3 for Drupal al... |
| CVE-2012-5545 | — | — | 0.9% | Dec 3, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the ShareThis module 7.x-2.x before 7.x-2.5 for Drupal allow remo... |
| CVE-2012-5544 | — | — | 1.1% | Dec 3, 2012 | The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links b... |
| CVE-2012-5543 | — | — | 1.2% | Dec 3, 2012 | The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properl... |
| CVE-2012-5542 | — | — | 0.7% | Dec 3, 2012 | Cross-site request forgery (CSRF) vulnerability in the Commerce Extra Panes module 7.x-1.x before 7.x-1.1 in Drupal allo... |
| CVE-2012-5541 | — | — | 1.2% | Dec 3, 2012 | Cross-site scripting (XSS) vulnerability in the Twitter Pull module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.0-rc... |
| CVE-2012-5540 | — | — | 1.2% | Dec 3, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the Hostip module 6.x-2.x before 6.x-2.2 and 7.x-2.x before 7.x-2... |
| CVE-2012-5539 | — | — | 1.0% | Dec 3, 2012 | The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, w... |
| CVE-2012-5538 | — | — | 0.9% | Dec 3, 2012 | Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1... |
| CVE-2012-5537 | — | — | 1.1% | Dec 3, 2012 | The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send sched... |
| CVE-2012-5534 | — | — | 4.4% | Dec 3, 2012 | The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitra... |
| CVE-2012-5450 | — | — | 0.9% | Dec 3, 2012 | Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.... |
| CVE-2012-5367 | — | — | 1.3% | Dec 3, 2012 | Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbi... |
| CVE-2012-3432 | — | — | 0.6% | Dec 3, 2012 | The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM g... |
| CVE-2012-2934 | — | — | 0.5% | Dec 3, 2012 | Xen 4.0, and 4.1, when running a 64-bit PV guest on "older" AMD CPUs, does not properly protect against a certain AMD pr... |
| CVE-2012-1599 | — | — | 1.0% | Dec 3, 2012 | Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrat... |
| CVE-2012-1598 | — | — | 1.3% | Dec 3, 2012 | Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "passwo... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now