Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kacper szurek vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2017-11155
An information exposure vulnerability in index.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to obtain sensitive system information via unspecified vectors.
Synology Photo Station 6.3-2967
Synology Photo Station
1 EDB exploit
9.8
CVSSv3
CVE-2017-11151
A vulnerability in synotheme_upload.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to upload arbitrary files without authentication via the logo_upload action.
Synology Photo Station
Synology Photo Station 6.3-2967
1 EDB exploit
9.8
CVSSv3
CVE-2017-11153
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to gain administrator privileges via a crafted serialized payload.
Synology Photo Station 6.3-2967
Synology Photo Station
1 EDB exploit
7.2
CVSSv3
CVE-2017-11154
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to create arbitrary PHP scripts via the type parameter.
Synology Photo Station
Synology Photo Station 6.3-2967
1 EDB exploit
NA
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote malicious users to execute arbitrary SQL commands via the time parameter to server/freichat.php.
Codelogic Freichat 9.6
1 EDB exploit
8.8
CVSSv3
CVE-2014-9013
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
Wpmarketplace Project Wpmarketplace 2.4.0
2 EDB exploits
4.3
CVSSv3
CVE-2014-9014
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin prior to 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.
Wpmarketplace Project Wpmarketplace 2.4.0
2 EDB exploits
NA
CVE-2014-9173
SQL injection vulnerability in view.php in the Google Doc Embedder plugin prior to 2.5.15 for WordPress allows remote malicious users to execute arbitrary SQL commands via the gpid parameter.
Google Doc Embedder Project Google Doc Embedder
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3