Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
unauthorized vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2002-1217
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote malicious users to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which byp...
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6.0
1 EDB exploit
6.7
CVSSv3
CVE-2018-0294
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local malicious user to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not...
Cisco Nx-os 7.3(2)n1(0.354)
Cisco Nx-os 5.2(1)sv3(1.10)
Cisco Nx-os 8.8(3.5)s0
Cisco Nx-os 7.0(3)i2(4a)
Cisco Firepower Extensible Operating System
Cisco Fxos
Cisco Nx-os 4.1(2)e1(1a)
NA
CVE-2007-2429
ManageEngine PasswordManager Pro (PMP) allows remote malicious users to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of t...
Manageengine Passwordmanager Pro
1 EDB exploit
9.8
CVSSv3
CVE-2023-37924
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0....
Apache Submarine
5.3
CVSSv3
CVE-2018-15429
A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote malicious user to access sensitive information on an affected system. The vulnerability is due to a lack of proper input and authorization of HTTP requests. An ...
Cisco Hyperflex Hx Data Platform 3.0(1a)
Cisco Hyperflex Hx Data Platform 2.6(1d)
NA
CVE-2004-2451
Roger Wilco 1.4.1.6 and previous versions, or Roger Wilco Base Station 0.30a or earlier, allows remote malicious users to send audio to arbitrary channels, aka the "Voices from the deep" bug.
1 EDB exploit
NA
CVE-2003-1176
post_message_form.asp in Web Wiz Forums 6.34 up to and including 7.5, when quote mode is used, allows remote malicious users to read or write to private forums by modifying the FID (forum ID) parameter.
Bdc Enterprises Web Wiz Forums 7.5
Bdc Enterprises Web Wiz Forums 6.34
Bdc Enterprises Web Wiz Forums 7.01
1 EDB exploit
7.1
CVSSv3
CVE-2018-0092
A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenticated, local malicious user to improperly delete valid user accounts. The network-operator role should not be able to delete other configured users on the devic...
Cisco Nx-os 7.0(3)i5(2)
Cisco Nx-os 7.0(3)i6(1)
Cisco Nx-os 7.0(3)i7(1)
NA
CVE-2015-5602
sudoedit in Sudo prior to 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."
Sudo Project Sudo
1 EDB exploit
2 Github repositories
NA
CVE-2002-0300
gnujsp 1.0.0 and 1.0.1 allows remote malicious users to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the ...
Gnujsp Gnujsp 1.0.1
Gnujsp Gnujsp 1.0.0
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »