Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : [1] 2 3 4 5 6 7 8 9 10 11 ...Result(s) : 116385

Alerts Feed Alerts

DateNameCategoriesDetail
N/A2017-09-25CVE-2017-14683cve geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
N/A2017-09-25CVE-2017-14506cve geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file.
6.82017-09-24GLSA-201709-22Gentoo Oracle JDK/JRE, IcedTea: Multiple vulnerabilities
7.52017-09-24GLSA-201709-21Gentoo PHP: Multiple vulnerabilities
N/A2017-09-24GLSA-201709-20Gentoo Postfix: Privilege escalation
2.12017-09-24GLSA-201709-19Gentoo Exim: Local privilege escalation
92017-09-24GLSA-201709-18Gentoo Mercurial: Multiple vulnerabilities
5.12017-09-24GLSA-201709-17Gentoo CVS: Command injection
9.32017-09-24GLSA-201709-16Gentoo Adobe Flash Player: Multiple vulnerabilities
N/A2017-09-24GLSA-201709-15Gentoo Chromium: Multiple vulnerabilities
N/A2017-09-23CVE-2017-14727cve logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
N/A2017-09-23CVE-2017-14726cve Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
N/A2017-09-23CVE-2017-14725cve Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
N/A2017-09-23CVE-2017-14724cve Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
N/A2017-09-23CVE-2017-14723cve Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and the...
N/A2017-09-23CVE-2017-14722cve Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
N/A2017-09-23CVE-2017-14721cve Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
N/A2017-09-23CVE-2017-14720cve Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
N/A2017-09-23CVE-2017-14719cve Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
N/A2017-09-23CVE-2017-14718cve Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
Page(s) : [1] 2 3 4 5 6 7 8 9 10 11 ...Result(s) : 116385