Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2014-2293
Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or exec…
Zikula Application Framework
after 1.3.6
CRITICAL 9.8
CVE-2016-9835
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to laun…
Zikula Application Framework
Patch available
MEDIUM 5.0
CVE-2011-3826
Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e…
Zikula
Mitigation only
MEDIUM 6.8
CVE-2011-0535
Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of ad…
Zikula Application Framework
after 1.2.4
MEDIUM 6.8
CVE-2010-4729
Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier f…
Zikula Application Framework
after 1.2.2
MEDIUM 5.0
CVE-2010-4728
Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protecti…
Zikula Application Framework
after 1.2.5
MEDIUM 6.8
CVE-2010-1732
Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to hijack th…
Zikula Application Framework
after 1.2.2