Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
web project web vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2015-5497
Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x prior to 6.x-2.6 and 7.x-1.x prior to 7.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
Web Links Project Web Links 6.x-2.0
Web Links Project Web Links 7.x-1.0
Web Links Project Web Links 7.x-1.x
Web Links Project Web Links 6.x-2.5
Web Links Project Web Links 6.x-2.4
Web Links Project Web Links 6.x-2.2
Web Links Project Web Links 6.x-2.3
Web Links Project Web Links 6.x-2.1
6.4
CVSSv2
CVE-2014-9022
The Webform Component Roles module 6.x-1.x prior to 6.x-1.8 and 7.x-1.x prior to 7.x-1.8 for Drupal allows remote malicious users to bypass the "disabled" restriction and modify read-only components via a crafted form.
Web Component Roles Project Web Component Roles 6.x-1.6
Web Component Roles Project Web Component Roles 7.x-1.4
Web Component Roles Project Web Component Roles 7.x-1.6
Web Component Roles Project Web Component Roles 7.x-1.0
Web Component Roles Project Web Component Roles 7.x-1.1
Web Component Roles Project Web Component Roles 7.x-1.2
Web Component Roles Project Web Component Roles 7.x-1.3
Web Component Roles Project Web Component Roles 6.x-1.5
Web Component Roles Project Web Component Roles 7.x-1.5
Web Component Roles Project Web Component Roles 7.x-1.7
5
CVSSv2
CVE-2015-4345
The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x prior to 7.x-1.5 and 7.x-2.x prior to 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote malicious users to obtain sensitive information via unspecified vectors.
Restful Web Services Project Restful Web Services 7.x-1.2
Restful Web Services Project Restful Web Services 7.x-1.1
Restful Web Services Project Restful Web Services 7.x-1.0
Restful Web Services Project Restful Web Services 7.x-2.0
Restful Web Services Project Restful Web Services 7.x-1.3
Restful Web Services Project Restful Web Services 7.x-2.1
Restful Web Services Project Restful Web Services 7.x-1.4
Restful Web Services Project Restful Web Services 7.x-2.2
NA
CVE-2021-4236
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handle...
Web Project Web
6.8
CVSSv2
CVE-2013-4225
The RESTful Web Services (restws) module 7.x-1.x prior to 7.x-1.4 and 7.x-2.x prior to 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create ...
Restful Web Services Project Restful Web Services
Restful Web Services Project Restful Web Services 7.x-2.x
6.8
CVSSv2
CVE-2019-10181
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
Icedtea-web Project Icedtea-web
Icedtea-web Project Icedtea-web 1.8.2
Debian Debian Linux 8.0
Opensuse Leap 15.0
1 Github repository
6.4
CVSSv2
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, ...
Icedtea-web Project Icedtea-web
Icedtea-web Project Icedtea-web 1.8.2
Debian Debian Linux 8.0
Opensuse Leap 15.0
1 Github repository
7.5
CVSSv2
CVE-2022-0766
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web before 0.6.17.
Calibre-web Project Calibre-web
7.5
CVSSv2
CVE-2022-0767
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web before 0.6.17.
Calibre-web Project Calibre-web
NA
CVE-2022-2525
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web before 0.6.20.
Calibre-web Project Calibre-web
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »