Main entries ~3682 :
Date Id Summary Products Score Patch Annotated
2012-09-17 CVE-2011-4960 SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Silverstripe N/A
2012-09-17 CVE-2011-4959 SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Silverstripe N/A
2014-04-08 CVE-2011-4958 Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/. Silverstripe N/A
2012-06-21 CVE-2011-4914 The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket. Linux_kernel, Suse_linux_enterprise_server N/A
2012-06-21 CVE-2011-4913 The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket. Linux_kernel, Suse_linux_enterprise_server N/A
2011-12-14 CVE-2011-4814 Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php. Dolibarr_erp\/crm N/A
2011-12-14 CVE-2011-4802 Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sortfield, (2) sortorder, and (3) sall parameters to user/index.php and (b) user/group/index.php; the id parameter to (4) info.php, (5) perms.php, (6) param_ihm.php, (7) note.php, and (8) fiche.php in user/; and (9) rowid parameter to admin/boxes.php. Dolibarr_erp\/crm N/A
Remaining NVD entries (unprocessed / no code available): ~295032 :
Date Id Summary Products Score Patch
2025-07-06 CVE-2025-7076 A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. N/A 5.4
2025-07-06 CVE-2025-7075 A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. N/A 6.3
2025-07-05 CVE-2023-5361 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A
2025-07-05 CVE-2023-6726 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A
2025-07-05 CVE-2023-6770 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A
2025-07-05 CVE-2023-6818 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A
2025-07-05 CVE-2023-6820 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A