Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
securify vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-2178
Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, prior to 1.0.5.9 on RV120W devices, and prior to 1.0.4.14 on RV180 and RV180W devices allows remote malicious users to hijack the authentication ...
Cisco Rv180 Firmware
Cisco Rv180w -
Cisco Rv180 -
Cisco Rv220w Firmware
Cisco Rv220w -
Cisco Rv120w Firmware
Cisco Rv120w -
7.8
CVSSv3
CVE-2017-8665
The Xamarin.iOS update component on systems running macOS allows an malicious user to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."
Microsoft Xamarin.ios
1 EDB exploit
8.8
CVSSv3
CVE-2020-4280
IBM QRadar SIEM 7.3 and 7.4 could allow a remote malicious user to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit ...
Ibm Qradar Security Information And Event Manager
Ibm Qradar Security Information And Event Manager 7.3.3
4.2
CVSSv3
CVE-2017-0140
Microsoft Edge allows remote malicious users to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.
Microsoft Edge
3 Github repositories
9.8
CVSSv3
CVE-2017-0372
Parameters injection in the SyntaxHighlight extension of Mediawiki prior to 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
Mediawiki Mediawiki 1.27.1
Mediawiki Mediawiki 1.28.0
Mediawiki Mediawiki
Mediawiki Mediawiki 1.27.2
Mediawiki Mediawiki 1.27.0
Mediawiki Mediawiki 1.28.1
Debian Debian Linux 9.0
Debian Debian Linux 7.0
6.1
CVSSv3
CVE-2018-6882
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) prior to 8.7 Patch 1 and 8.8.x prior to 8.8.7 might allow remote malicious users to inject arbitrary web script or HTML via a Content-Location header i...
Synacor Zimbra Collaboration Suite 8.8.4
Synacor Zimbra Collaboration Suite 8.8.6
Synacor Zimbra Collaboration Suite 8.7
Synacor Zimbra Collaboration Suite 8.8.0
Synacor Zimbra Collaboration Suite 8.8.1
Synacor Zimbra Collaboration Suite 8.8.2
Synacor Zimbra Collaboration Suite 8.8.3
Synacor Zimbra Collaboration Suite
Synacor Zimbra Collaboration Suite 8.8.5
7.5
CVSSv3
CVE-2020-4269
IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-ForceID: 175845.
Ibm Qradar Security Information And Event Manager 7.3.3
Ibm Qradar Security Information And Event Manager
7.8
CVSSv3
CVE-2020-4270
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.
Ibm Qradar Security Information And Event Manager 7.3.3
Ibm Qradar Security Information And Event Manager
6.3
CVSSv3
CVE-2020-4271
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897.
Ibm Qradar Security Information And Event Manager
Ibm Qradar Security Information And Event Manager 7.3.3
8.8
CVSSv3
CVE-2020-4272
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote malicious user to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the malicious user to execute arbitrary code on the vulnerab...
Ibm Qradar Security Information And Event Manager
Ibm Qradar Security Information And Event Manager 7.3.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »