Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
action view project action view vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2020-15169
In Action View prior to 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS a...
Action View Project Action View
Debian Debian Linux 10.0
Fedoraproject Fedora 33
5.4
CVSSv3
CVE-2021-24605
The create_post_page AJAX action of the Custom Post View Generator WordPress plugin up to and including 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue
Custom Post View Generator Project Custom Post View Generator
9.8
CVSSv3
CVE-2018-5987
SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay a...
Social Pinboard Project Social Pinboard 2.0
1 EDB exploit
NA
CVE-2007-6127
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and previous versions allow remote malicious users to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to...
Project Alumni Project Alumni
1 EDB exploit
NA
CVE-2007-6126
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable th...
Project Alumni Project Alumni
Project Alumni Project Alumni 1.0.8
1 EDB exploit
6.1
CVSSv3
CVE-2017-15216
MISP prior to 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
Misp-project Misp
NA
CVE-2009-1480
SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote malicious users to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors.
Pragyan Cms Project Pragyan Cms 2.6.4
1 EDB exploit
6.5
CVSSv3
CVE-2020-29604
An issue exists in MantisBT prior to 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues) to use the COPY group action to create a clone, including all bugnotes and attachments, of any private issue (i.e., one having Private ...
Mantisbt Mantisbt
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started