Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
email log project email log vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2021-24758
The Email Log WordPress plugin prior to 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections
Email Log Project Email Log
4.3
CVSSv2
CVE-2021-24924
The Email Log WordPress plugin prior to 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue
Email Log Project Email Log
4.3
CVSSv2
CVE-2022-1630
The WP-EMail WordPress plugin prior to 2.69.0 does not protect its log deletion functionality with nonce checks, allowing malicious user to make a logged in admin delete logs via a CSRF attack
Wp-email Project Wp-email
5
CVSSv2
CVE-2021-25009
The CorreosExpress WordPress plugin up to and including 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
Correosexpress Project Correosexpress
10
CVSSv2
CVE-2008-4796
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and previous versions, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote malicious users to execute arbitrary commands vi...
Snoopy Project Snoopy
Debian Debian Linux 4.0
Debian Debian Linux 5.0
Nagios Nagios
Wordpress Wordpress
7.1
CVSSv2
CVE-2014-9472
The email gateway in RT (aka Request Tracker) 3.0.0 up to and including 4.x prior to 4.0.23 and 4.2.x prior to 4.2.10 allows remote malicious users to cause a denial of service (CPU and disk consumption) via a crafted email.
Debian Debian Linux 7.0
Fedoraproject Fedora 22
Fedoraproject Fedora 21
Bestpractical Request Tracker 3.8.16
Bestpractical Request Tracker 3.8.17
Bestpractical Request Tracker 4.0.0
Bestpractical Request Tracker 4.0.1
Bestpractical Request Tracker 4.0.14
Bestpractical Request Tracker 4.0.15
Bestpractical Request Tracker 4.0.16
Bestpractical Request Tracker 4.0.17
Bestpractical Request Tracker 4.0.18
Bestpractical Request Tracker 4.2.8
Bestpractical Request Tracker 4.2.9
Bestpractical Request Tracker 3.6.10
Bestpractical Request Tracker 3.8.3
Bestpractical Request Tracker 3.8.13
Bestpractical Request Tracker 3.8.15
Bestpractical Request Tracker 4.0.2
Bestpractical Request Tracker 4.0.4
Bestpractical Request Tracker 4.0.11
Bestpractical Request Tracker 4.0.13
4.3
CVSSv2
CVE-2009-0500
Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 prior to 1.6.9, 1.7 prior to 1.7.7, 1.8 prior to 1.8.8, and 1.9 prior to 1.9.4 allows remote malicious users to inject arbitrary web script or HTML via crafted log table information that is not properly hand...
Moodle Moodle 1.7.1
Moodle Moodle 1.7.2
Moodle Moodle 1.8.2
Moodle Moodle 1.8.3
Moodle Moodle 1.8.7
Moodle Moodle 1.9.3
Moodle Moodle 1.6.6
Moodle Moodle 1.6.8
Moodle Moodle 1.7.3
Moodle Moodle 1.7.4
Moodle Moodle 1.8.4
Moodle Moodle 1.8.6
Moodle Moodle 1.6.7
Moodle Moodle 1.6.3
Moodle Moodle 1.6.5
Moodle Moodle 1.7.5
Moodle Moodle 1.7.6
Moodle Moodle 1.8.5
Moodle Moodle 1.9.2
Moodle Moodle 1.6.0
Moodle Moodle 1.6.4
Moodle Moodle 1.8.1
NA
CVE-2022-36056
Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions before 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should hav...
Sigstore Cosign
6.8
CVSSv2
CVE-2006-3636
Multiple cross-site scripting (XSS) vulnerabilities in Mailman prior to 2.1.9rc1 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Gnu Mailman 2.1.1
Gnu Mailman 2.1.7
Gnu Mailman 2.1.8
Gnu Mailman 2.1.2
Gnu Mailman 2.1.3
Gnu Mailman 2.1b1
Gnu Mailman 2.1
Gnu Mailman 2.1.5.8
Gnu Mailman 2.1.6
Gnu Mailman 2.1.4
Gnu Mailman 2.1.5
1 EDB exploit
6.9
CVSSv2
CVE-2008-5153
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.
Moodle Moodle 1.8.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »