Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
call to action vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2015-8350
Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin prior to 2.5.1 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-...
Inboundnow Call To Action
6.5
CVSSv3
CVE-2018-19505
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution inv...
Bmc Remedy Action Request System Server 7.1
4.4
CVSSv3
CVE-2021-32638
Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter t...
Github Codeql Action
5.4
CVSSv3
CVE-2023-0551
The REST API TO MiniProgram WordPress plugin up to and including 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
Minapper Rest Api To Miniprogram
8.1
CVSSv3
CVE-2017-3200
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The ability to exploit this vulnerability depends ...
Graniteds Graniteds 3.1.1
9.8
CVSSv3
CVE-2017-3202
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The ability to exploit this ...
Exadel Flamingo 2.2.0
9.8
CVSSv3
CVE-2017-5983
The JIRA Workflow Designer Plugin in Atlassian JIRA Server prior to 6.3.0 improperly uses an XML parser and deserializer, which allows remote malicious users to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
Atlassian Jira 5.1.7
Atlassian Jira 6.2.3
Atlassian Jira 6.1.7
Atlassian Jira 5.1.1
Atlassian Jira 4.4.3
Atlassian Jira 4.3.4
Atlassian Jira 6.2.7
Atlassian Jira 6.0.8
Atlassian Jira 5.2.8
Atlassian Jira 4.4
Atlassian Jira 6.2
Atlassian Jira 5.0.3
Atlassian Jira 5.2.5
Atlassian Jira 5.0.5
Atlassian Jira 5.2.2
Atlassian Jira 5.0.4
Atlassian Jira 5.2.10
Atlassian Jira 5.2.3
Atlassian Jira 6.1.8
Atlassian Jira 6.1.2
Atlassian Jira 6.2.5
Atlassian Jira 4.3.2
8.1
CVSSv3
CVE-2017-3199
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI se...
Graniteds Graniteds 3.1.1
8.1
CVSSv3
CVE-2017-3201
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability t...
Exadel Flamingo Amf-serializer 2.2.0
9.8
CVSSv3
CVE-2017-3206
The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data ...
Exadel Flamingo 2.2.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »