9.3

CVSS4.0

CVE-2012-10054 - Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, a…

📅 Published: Aug. 13, 2025, 8:54 p.m. 🔄 Last Modified: April 7, 2026, 2:02 p.m.

10

CVSS4.0

CVE-2011-10013 - Traq 2.0–2.3 admincp/common.php RCE

Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to halt execution after a failed access check, allowing unauthenticated users to reach admin-only functionality. This can be exploited via plugins.php t…

📅 Published: Aug. 13, 2025, 8:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2012-10060 - Sysax Multi Server < 5.55 SSH Username Buffer Overflow

Sysax Multi Server versions prior to 5.55 contains a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-size stack buffer without proper bounds checking. This allows remote code execut…

📅 Published: Aug. 13, 2025, 8:53 p.m. 🔄 Last Modified: April 7, 2026, 2:02 p.m.

10

CVSS4.0

CVE-2011-10019 - Spreecommerce < 0.60.2 Search Parameter RCE

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arb…

📅 Published: Aug. 13, 2025, 8:53 p.m. 🔄 Last Modified: April 7, 2026, 2:02 p.m.

10

CVSS4.0

CVE-2011-10017 - Snort Report nmap.php/nbtscan.php RCE

Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentica…

📅 Published: Aug. 13, 2025, 8:53 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2011-10009 - S40 CMS 0.4.2 Path Traversal

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending travers…

📅 Published: Aug. 13, 2025, 8:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2011-10016 - Real Networks Netzip Classic 7.5.1.86 File Parsing Buffer Overflow

Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allow…

📅 Published: Aug. 13, 2025, 8:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2012-10058 - RabidHamster R4 Log Entry sprintf() Buffer Overflow

RabidHamster R4 v1.25 contains a stack-based buffer overflow vulnerability due to unsafe use of sprintf() when logging malformed HTTP requests. A remote attacker can exploit this flaw by sending a specially crafted URI, resulting in arbitrary code execution under the context of the web server proce…

📅 Published: Aug. 13, 2025, 8:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2011-10010 - QuickShare File Server 1.2.1 Path Traversal RCE

QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authenticated users can exploit this flaw by submitting crafted sequences to access or write files outside the intended virtual directory. When the "Writab…

📅 Published: Aug. 13, 2025, 8:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2012-10056 - PHP Volunteer Management System 1.0.2 Arbitrary File Upload

PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is publicly accessible…

📅 Published: Aug. 13, 2025, 8:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348202
Page 4200 of 34,821
« previous page » next page
Filters