Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
web project web vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2015-5497
Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x prior to 6.x-2.6 and 7.x-1.x prior to 7.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
Web Links Project Web Links 6.x-2.2
Web Links Project Web Links 6.x-2.5
Web Links Project Web Links 7.x-1.0
Web Links Project Web Links 7.x-1.x
Web Links Project Web Links 6.x-2.4
Web Links Project Web Links 6.x-2.1
Web Links Project Web Links 6.x-2.3
Web Links Project Web Links 6.x-2.0
NA
CVE-2014-9022
The Webform Component Roles module 6.x-1.x prior to 6.x-1.8 and 7.x-1.x prior to 7.x-1.8 for Drupal allows remote malicious users to bypass the "disabled" restriction and modify read-only components via a crafted form.
Web Component Roles Project Web Component Roles 7.x-1.1
Web Component Roles Project Web Component Roles 7.x-1.2
Web Component Roles Project Web Component Roles 7.x-1.6
Web Component Roles Project Web Component Roles 7.x-1.7
Web Component Roles Project Web Component Roles 7.x-1.3
Web Component Roles Project Web Component Roles 7.x-1.4
Web Component Roles Project Web Component Roles 6.x-1.6
Web Component Roles Project Web Component Roles 6.x-1.5
Web Component Roles Project Web Component Roles 7.x-1.0
Web Component Roles Project Web Component Roles 7.x-1.5
NA
CVE-2015-4345
The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x prior to 7.x-1.5 and 7.x-2.x prior to 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote malicious users to obtain sensitive information via unspecified vectors.
Restful Web Services Project Restful Web Services 7.x-2.0
Restful Web Services Project Restful Web Services 7.x-2.2
Restful Web Services Project Restful Web Services 7.x-1.0
Restful Web Services Project Restful Web Services 7.x-1.1
Restful Web Services Project Restful Web Services 7.x-1.3
Restful Web Services Project Restful Web Services 7.x-2.1
Restful Web Services Project Restful Web Services 7.x-1.4
Restful Web Services Project Restful Web Services 7.x-1.2
NA
CVE-2012-5556
Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x prior to 7.x-1.1 and 7.x-2.x prior to 7.x-2.0-alpha3 for Drupal allow remote malicious users to hijack the authentication of arbitrary users via unknown vectors.
Restful Web Services Project Restful Web Services 7.x-1.0
Restful Web Services Project Restful Web Services 7.x-1.x
Restful Web Services Project Restful Web Services 7.x-2.0
Restful Web Services Project Restful Web Services 7.x-2.x
NA
CVE-2013-1946
The RESTful Web Services (RESTWS) module 7.x-1.x prior to 7.x-1.3 and 7.x-2.x prior to 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote malicious users to cause a denial of service via a GET request with an...
Restful Web Services Project Restful Web Services 7.x-1.1
Restful Web Services Project Restful Web Services 7.x-1.2
Restful Web Services Project Restful Web Services 7.x-2.0
9.8
CVSSv3
CVE-2021-4236
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handle...
Web Project Web
NA
CVE-2013-0205
Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x prior to 7.x-1.2 and 7.x-2.x prior to 7.x-2.0-alpha4 for Drupal allows remote malicious users to hijack the authentication of arbitrary users via unknown vectors.
Restful Web Services Project Restful Web Services
Restful Web Services Project Restful Web Services 7.x-2.0
8.8
CVSSv3
CVE-2013-4225
The RESTful Web Services (restws) module 7.x-1.x prior to 7.x-1.4 and 7.x-2.x prior to 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create ...
Restful Web Services Project Restful Web Services
Restful Web Services Project Restful Web Services 7.x-2.x
8.1
CVSSv3
CVE-2019-10181
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
Icedtea-web Project Icedtea-web
Icedtea-web Project Icedtea-web 1.8.2
Debian Debian Linux 8.0
Opensuse Leap 15.0
1 Github repository
8.6
CVSSv3
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, ...
Icedtea-web Project Icedtea-web
Icedtea-web Project Icedtea-web 1.8.2
Debian Debian Linux 8.0
Opensuse Leap 15.0
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »