Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2011-3712 CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an … Cakephp No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3713EPSS 7% cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error… Cftp No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3714 ClanSphere 2010.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in… Clansphere No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3715 ClanTiger 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a… Clantiger No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3716 Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a… Claroline No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3717 ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in … Clipbucket No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3718 CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installa… Cms Made Simple No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3719 CodeIgniter 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in… Codeigniter No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3720 conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, whi… Conceptcms No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3721 concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the i… Concrete No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3722 Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the … Coppermine Photo Gallery No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3723 Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path … Crafty Syntax No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3724 CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an… Cubecart No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3725 DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e… Deluxebb No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3695 111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path… 111webcalendar No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3696 60cycleCMS 2.5.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in … 60cyclecms No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3697 Achievo 1.4.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an … Achievo No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3698 AdaptCMS 2.0.2 Beta allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path … Adaptcms No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3699 John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in… Adodb No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3700 Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in… Advanced Electron Forum No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3701 AlegroCart 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in … Alegrocart No fix yet Fix from $1,6002011-09-23 MEDIUM 5.0 CVE-2011-3702 Ananta Gazelle 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i… Ananta Gazelle No fix yet Fix from $1,6002011-09-23 HIGH 10.0 CVE-2011-3497EPSS 57% service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly relate… Scadapro after 4.0.0 Fix from $1,9502011-09-16 MEDIUM 5.0 CVE-2011-3502EPSS 6% The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trai… Cogent Datahub No fix yet Fix from $1,6002011-09-16 MEDIUM 5.0 CVE-2009-5101 Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, r… Bi Server after 1.7.0.1062 Fix from $1,6002011-09-13 HIGH 10.0 CVE-2011-1643 Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Pre… Unified Communications Manager Mitigation only Fix from $1,9502011-08-29 MEDIUM 5.0 CVE-2011-2737 RSA enVision 3.x and 4.x before 4 SP4 P3 allows remote attackers to read arbitrary files via unspecified vectors, related to an "arbitrary file retri… Envision after 4.0 Fix from $1,6002011-08-25 MEDIUM 5.0 CVE-2011-3264 Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installa… Zabbix after 1.8.5 Fix from $1,6002011-08-19 MEDIUM 5.0 CVE-2011-3265 popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter. Zabbix after 1.8.6 Fix from $1,6002011-08-19 MEDIUM 5.0 CVE-2011-2986 Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used o… Firefox after 5.0 Fix from $1,6002011-08-18