Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

7,928 results · Page 25/159
7.5
CVE-2013-7349

Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (

7.5
CVE-2014-2034

Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user ac

7.5
CVE-2014-0050

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,

7.5
CVE-2014-0635

Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web se

7.5
CVE-2014-1691

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to c

7.5
CVE-2013-3213

Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL

7.5
CVE-2013-0735

Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow rem

7.5
CVE-2012-5648

Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands

7.5
CVE-2014-0592

Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bri

7.5
CVE-2014-2210

Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive infor

7.5
CVE-2014-0160 KEV

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe

7.5
CVE-2011-5277

Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4

7.5
CVE-2011-5278

SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allow

7.5
CVE-2012-6643

Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow

7.5
CVE-2014-2543

Buffer overflow in the Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and R

7.5
CVE-2014-1716

Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Goo

7.5
CVE-2014-1717

Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed a

7.5
CVE-2014-1718

Integer overflow in the SoftwareFrameManager::SwapToNewFrame function in content/browser/renderer_host/software_frame_ma

7.5
CVE-2014-1719

Use-after-free vulnerability in the WebSharedWorkerStub::OnTerminateWorkerContext function in content/worker/websharedwo

7.5
CVE-2014-1720

Use-after-free vulnerability in the HTMLBodyElement::insertedInto function in core/html/HTMLBodyElement.cpp in Blink, as

7.5
CVE-2014-1721

Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows

7.5
CVE-2014-1722

Use-after-free vulnerability in the RenderBlock::addChildIgnoringAnonymousColumnBlocks function in core/rendering/Render

7.5
CVE-2014-1723

The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly ha

7.5
CVE-2014-1724

Use-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher 0.7.1, as used in Google Chrome before 34.0.184

7.5
CVE-2014-1727

Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome before 34.0.1847.116 a

7.5
CVE-2014-1728

Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.116 allow attackers to cause a denial of service

7.5
CVE-2014-1729

Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allo

7.5
CVE-2014-2544

Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in

7.5
CVE-2014-1455

SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, p

7.5
CVE-2014-2708

Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to

7.5
CVE-2013-7355

SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL comman

7.5
CVE-2013-7360

Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown ve

7.5
CVE-2013-7362

An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.

7.5
CVE-2013-7363

Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensi

7.5
CVE-2013-7364

An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows rem

7.5
CVE-2013-7367

SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attac

7.5
CVE-2014-2748

The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or

7.5
CVE-2014-2751

SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access v

7.5
CVE-2014-2752

SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote att

7.5
CVE-2014-2540

SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitra

7.5
CVE-2014-2847

SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands

7.5
CVE-2014-0763

An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll i

7.5
CVE-2014-0764

By providing an overly long string to the NodeName parameter, an attacker may be able to overflow the static stack buff

7.5
CVE-2014-0765

To exploit this vulnerability, the attacker sends data from the GotoCmd argument to control. If the value of the argume

7.5
CVE-2014-0766

An attacker can exploit this vulnerability by copying an overly long NodeName2 argument into a statically sized buffer

7.5
CVE-2014-0767

An attacker may exploit this vulnerability by passing an overly long value from the AccessCode argument to the control.

7.5
CVE-2014-0768

An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buf

7.5
CVE-2014-0770

By providing an overly long string to the UserName parameter, an attacker may be able to overflow the static stack buff

7.5
CVE-2014-0771

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter a

7.5
CVE-2014-0773

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure

Scan for 2014 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started