Vulnerabilities (CVE)

Total 393889 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-6695 1 Gehealthcare 1 Centricity Pacs Workstation 2026-06-16 10.0 HIGH N/A
GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of ddpadmin for the ddpadmin user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.
CVE-2012-6694 1 Gehealthcare 2 Centricity Pacs Server, Centricity Pacs Workstation 2026-06-16 10.0 HIGH N/A
GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1, and Server 4.0, has a password of 2charGE for the geservice account, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.
CVE-2012-6693 1 Gehealthcare 1 Centricity Pacs Server 2026-06-16 10.0 HIGH N/A
GE Healthcare Centricity PACS 4.0 Server has a default password of (1) nasro for the nasro (ReadOnly) user and (2) nasrw for the nasrw (Read/Write) user, which has unspecified impact and attack vectors.
CVE-2012-6692 1 Yoast 1 Wordpress Seo 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_title parameter to wp-admin/post-new.php, which is not properly handled in the snippet preview functionality.
CVE-2012-6691 1 Oscmax 1 Oscmax 2026-06-16 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php.
CVE-2012-6689 1 Linux 1 Linux Kernel 2026-06-16 7.2 HIGH 7.8 HIGH
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
CVE-2012-6687 1 Fastcgi 1 Fcgi 2026-06-16 5.0 MEDIUM N/A
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
CVE-2012-6685 2 Nokogiri, Redhat 8 Nokogiri, Cloudforms Management Engine, Enterprise Mrg and 5 more 2026-06-16 5.0 MEDIUM 7.5 HIGH
Nokogiri before 1.5.4 is vulnerable to XXE attacks
CVE-2012-6684 2 Debian, Redcloth 2 Debian Linux, Redcloth Library 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.
CVE-2012-6682 1 Dragonbyte-tech 1 Vbdownloads Module 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter.
CVE-2012-6671 1 Dragonbyte-tech 1 Forumon Rpg Module 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attackers to inject arbitrary web script or HTML via the (1) monster[title] or (2) monster[description] parameters.
CVE-2012-6670 1 Dragonbyte-tech 1 Vbactivity Module 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the reason parameter in (1) actions/nominatemedal.php or (2) actions/requestmedal.php.
CVE-2012-6668 1 Dragonbyte-tech 1 Vbshout Module 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the (1) reportreason parameter in actions/doreport.php or (2) modnotes parameter in actions/updatereport.php.
CVE-2012-6667 1 Dragonbyte-tech 1 Vbshout 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.
CVE-2012-6666 1 Vbseo 1 Vbseo 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.
CVE-2012-6665 1 Phpmoneybooks 1 Phpmoneybooks 2026-06-16 4.3 MEDIUM N/A
Directory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2012-1669. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue might have been fixed in 1.0.3.
CVE-2012-6664 2026-06-16 N/A 9.1 CRITICAL
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.
CVE-2012-6663 1 Ge 4 D200, D200 Firmware, D20me and 1 more 2026-06-16 5.0 MEDIUM 7.5 HIGH
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
CVE-2012-6662 2 Jqueryui, Redhat 5 Jquery Ui, Enterprise Linux Desktop, Enterprise Linux Hpc Node and 2 more 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.
CVE-2012-6661 2 Plone, Zope 2 Plone, Zope 2026-06-16 5.0 MEDIUM N/A
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).