Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
key vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-4564
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus...
Ibm Security Key Lifecycle Manager
7.5
CVSSv3
CVE-2019-4565
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, which makes it easier for malicious users to compromise user accounts. IBM X-Force ID: 166626.
Ibm Security Key Lifecycle Manager
5.5
CVSSv3
CVE-2019-4566
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 166627.
Ibm Security Key Lifecycle Manager
6.1
CVSSv3
CVE-2021-36760
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the J...
Wso2 Api Manager 3.0.0
Wso2 Api Manager 3.1.0
Wso2 Api Manager 3.2.0
Wso2 Api Manager 4.0.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
Wso2 Identity Server 5.9.0
Wso2 Identity Server 5.10.0
Wso2 Identity Server 5.11.0
Wso2 Identity Server As Key Manager 5.3.0
Wso2 Identity Server As Key Manager 5.5.0
Wso2 Identity Server As Key Manager 5.6.0
Wso2 Identity Server As Key Manager 5.7.0
Wso2 Identity Server As Key Manager 5.9.0
Wso2 Identity Server As Key Manager 5.10.0
Wso2 Iot Server 3.3.1
4.3
CVSSv3
CVE-2022-29453
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
Ayecode Api Key For Google Maps
NA
CVE-2002-2403
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote malicious users to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
Key Focus Kf Web Server 1.0.8
1 EDB exploit
NA
CVE-2010-1904
SQL injection vulnerability in EMC RSA Key Manager (RKM) C Client 1.5.x allows user-assisted remote malicious users to execute arbitrary SQL commands via the metadata section of encrypted key data.
Emc Rsa Key Manager Client 1.5.0
NA
CVE-2002-1031
KeyFocus (KF) web server 1.0.2 allows remote malicious users to list directories and read restricted files via an HTTP request containing a %00 (null) character.
Key Focus Kf Web Server 1.0.2
1 EDB exploit
NA
CVE-2001-1169
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.
Bell Communications Research S Key Gold
NA
CVE-2007-3396
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote malicious users to inject arbitrary web script or HTML via the opsubmenu parameter.
Key Focus Kf Web Server 3.1.0
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »