Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2020-5188
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
Dotnetnuke
after 9.4.4
MEDIUM 5.4
CVE-2020-5186
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
Dotnetnuke
after 9.4.4
MEDIUM 6.1
CVE-2019-12562EPSS 6%
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin n…
Dotnetnuke
9.4.0+
HIGH 7.5
CVE-2018-15811 KEVEPSS 74%
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Dotnetnuke
after 9.2.1
HIGH 7.5
CVE-2018-15812EPSS 47%
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
Dotnetnuke
after 9.2.1
HIGH 7.5
CVE-2018-18325 KEVEPSS 74%
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete…
Dotnetnuke
after 9.2.2
HIGH 7.5
CVE-2018-18326EPSS 54%
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue …
Dotnetnuke
after 9.2.2
MEDIUM 6.1
CVE-2018-14486
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
Dotnetnuke
No fix yet
HIGH 7.5
CVE-2017-0929EPSS 13%
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able…
Dotnetnuke
9.2.0+
HIGH 8.8
CVE-2017-9822 KEVEPSS 95%
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Dotnetnuke
9.1.1+
CRITICAL 9.8
CVE-2015-2794EPSS 75%
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct …
Dotnetnuke
after 07.04.00
MEDIUM 5.4
CVE-2016-7119
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to …
Dotnetnuke
after 08.00.04
MEDIUM 5.0
CVE-2009-4109
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need…
Dotnetnuke
Mitigation only
HIGH 7.5
CVE-2008-7102
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unk…
Dotnetnuke
Patch available
MEDIUM 6.5
CVE-2008-7100
Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknow…
Dotnetnuke
Patch available
MEDIUM 5.0
CVE-2008-7101
Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessin…
Dotnetnuke
Patch available
MEDIUM 6.8
CVE-2008-6541
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files a…
Dotnetnuke
after 4.8.1
MEDIUM 5.1
CVE-2008-6540
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey val…
Dotnetnuke
after 4.8.1
MEDIUM 6.4
CVE-2008-6399
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack …
Dotnetnuke
Mitigation only
HIGH 10.0
CVE-2006-3601
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privile…
Dotnetnuke
No fix yet
HIGH 7.5
CVE-2004-2324
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database vi…
Dotnetnuke
Patch available
MEDIUM 5.0
CVE-2004-2323
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server userna…
Dotnetnuke
Patch available