Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kingskrupellos vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2016-10379
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.
Virtuemart Virtuemart 3.0.14
7.5
CVSSv3
CVE-2017-5214
The Codextrous B2J Contact (aka b2j_contact) extension prior to 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a time value. This makes it easier to read arbitrary uploaded files.
Codextrous B2j Contact
NA
CVE-2006-6945
SQL injection vulnerability in Virtuemart 1.0.7 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors, probably related to (1) Itemid, (2) product_id, and category_id parameters as handled in virtuemart_parser.php.
Virtuemart Virtuemart 1.0.7
9.8
CVSSv3
CVE-2017-5215
The Codextrous B2J Contact (aka b2j_contact) extension prior to 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protection mechanism, leading to remote code execution.
Codextrous B2j Contact
NA
CVE-2011-0908
Open redirect vulnerability in Vanilla Forums prior to 2.0.17.6 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Vanillaforums Vanilla 2.0.11
Vanillaforums Vanilla 2.0.12
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.4
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.16
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.10
Vanillaforums Vanilla 2.0.9
Vanillaforums Vanilla 2.0.17.1
7.5
CVSSv3
CVE-2017-9030
The Codextrous B2J Contact (aka b2j_contact) extension prior to 2.1.13 for Joomla! allows a directory traversal attack that bypasses a uniqid protection mechanism, and makes it easier to read arbitrary uploaded files.
Codextrous B2j Contact
NA
CVE-2007-3247
SQL injection vulnerability in VirtueMart prior to 1.0.11 allows remote malicious users to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.
Virtuemart Virtuemart
NA
CVE-2010-2678
SQL injection vulnerability in xmap (com_xmap) component for Joomla! allows remote malicious users to execute arbitrary SQL commands via the Itemid parameter to index.php.
Guillermo Vargas Com Xmap
NA
CVE-2008-1427
SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote malicious users to execute arbitrary SQL commands via the mailingid parameter in a mailing view action to index.php.
Joobi Acajoom 1.1.5
Joobi Acajoom 1.2.5
Joomla Com Acajoom 1.1.5
Joomla Com Acajoom 1.2.5
1 EDB exploit
NA
CVE-2010-2255
SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component prior to 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component prior to 1.2 for Joomla! allows remote malicious users to execute arbitrary SQL commands via the ...
Tamlyncreative Com Bfsurvey Profree 1.2.6
Tamlyncreative Com Bfsurvey Pro
Tamlyncreative Com Bfsurvey Basic
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »