Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earli
CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary
The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts d
The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not p
The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object ret
The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of value
The JavaScript implementation in Opera 10.5 does not properly restrict the set of values contained in the object returne
The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object re
Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names
Dragonfly in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unspecified
Unspecified vulnerability in the Web Workers implementation in Opera before 11.60 allows remote attackers to cause a den
Opera before 11.60 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified con
Mozilla Firefox 8.0.1 and earlier does not prevent capture of data about the times of Same Origin Policy violations duri
Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Origin Policy violation
Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME
Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data abo
The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allo
dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcp
Multiple directory traversal vulnerabilities in namazu.cgi in Namazu before 2.0.16 allow remote attackers to read arbitr
Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arb
Directory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files v
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
Google Chrome before 16.0.912.63 does not properly perform regex matching, which allows remote attackers to cause a deni
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bound
The PDF parser in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service (out-of-bounds r
Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial
The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properl
Google Chrome before 16.0.912.63 does not properly handle YUV video frames, which allows remote attackers to cause a den
Google Chrome before 16.0.912.63 does not properly handle PDF documents, which allows remote attackers to cause a denial
Google Chrome before 16.0.912.63 does not properly handle PDF cross references, which allows remote attackers to cause a
Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attack
Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read
The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a co
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not include the HTTPOnly flag in
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address withi
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which a
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP respons
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not include the HTTPOnly flag in a Set-Cookie h
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web p
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are n
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which make
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not prevent the use of weak ciphers for SSL
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that ar
SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query
Scan for 2011 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started