Note:
This project will be discontinued after December 13, 2021. [more]
Main entries ~3682 :
Remaining NVD entries (unprocessed / no code available): ~301148 :
| Date | Id | Summary | Products | Score | Patch | Annotated |
|---|---|---|---|---|---|---|
| 2012-06-21 | CVE-2011-0006 | The ima_lsm_rule_init function in security/integrity/ima/ima_policy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunistic circumstances by leveraging an administrator's addition of an IMA rule for LSM. | Linux_kernel | N/A | ||
| 2017-04-24 | CVE-2010-5329 | The video_usercopy function in drivers/media/video/v4l2-ioctl.c in the Linux kernel before 2.6.39 relies on the count value of a v4l2_ext_controls data structure to determine a kmalloc size, which might allow local users to cause a denial of service (memory consumption) via a large value. | Linux_kernel | 5.5 | ||
| 2017-02-06 | CVE-2010-5328 | include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper process, which allows local users to cause a denial of service (system crash) by leveraging access to this process group. | Linux_kernel | 5.5 | ||
| 2017-01-13 | CVE-2010-5327 | Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template. | Liferay_portal | 8.8 | ||
| 2014-11-30 | CVE-2010-5313 | Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842. | Linux_kernel | N/A | ||
| 2014-11-24 | CVE-2010-5312 | Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. | Drill, Debian_linux, Drupal, Fedora, Jquery_ui, Snapcenter | 6.1 | ||
| 2012-08-08 | CVE-2010-5142 | chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI. | Chef | N/A |
| Date | Id | Summary | Products | Score | Patch |
|---|---|---|---|---|---|
| 2025-08-20 | CVE-2025-9173 | A weakness has been identified in Emlog Pro up to 2.5.18. This issue affects some unknown processing of the file /admin/media.php?action=upload&sid=0. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | N/A | 6.3 | |
| 2025-08-20 | CVE-2025-57727 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference | N/A | N/A | |
| 2025-08-20 | CVE-2025-57728 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files | N/A | N/A | |
| 2025-08-20 | CVE-2025-57729 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start | N/A | N/A | |
| 2025-08-20 | CVE-2025-57730 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature | N/A | N/A | |
| 2025-08-20 | CVE-2025-57731 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content | N/A | N/A | |
| 2025-08-20 | CVE-2025-57732 | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership | N/A | N/A |