Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
management console vulnerabilities and exploits
(subscribe to this query)
6.3
CVSSv3
CVE-2022-1462
An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition using ioctls TIOCSPTLCK and TIOCGPTPEER and TIOCSTI and TCXONC with leakage of memory in the flush_to_ldisc function. This flaw allows a l...
Linux Linux Kernel -
Redhat Enterprise Linux 8.0
Redhat Enterprise Linux 9.0
Debian Debian Linux 10.0
7.8
CVSSv3
CVE-2022-1679
A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the sys...
Linux Linux Kernel
Debian Debian Linux 10.0
Netapp H410c Firmware -
Netapp H300s Firmware -
Netapp H500s Firmware -
Netapp H700s Firmware -
Netapp H300e Firmware -
Netapp H500e Firmware -
Netapp H700e Firmware -
Netapp H410s Firmware -
2 Github repositories
9.1
CVSSv3
CVE-2021-42646
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10...
Wso2 Api Manager 2.6.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server As Key Manager 5.7.0
Wso2 Identity Server 5.8.0
Wso2 Api Manager 3.0.0
Wso2 Api Manager 3.1.0
Wso2 Identity Server As Key Manager 5.9.0
Wso2 Identity Server As Key Manager 5.10.0
Wso2 Identity Server 5.11.0
Wso2 Api Manager 4.0.0
Wso2 Api Manager 3.2.0
Wso2 Identity Server 5.9.0
Wso2 Identity Server 5.10.0
9.8
CVSSv3
CVE-2022-28005
An issue exists in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that ...
3cx 3cx
6.1
CVSSv3
CVE-2022-29548
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator...
Wso2 Api Manager 2.6.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server As Key Manager 5.7.0
Wso2 Enterprise Integrator 6.5.0
Wso2 Api Microgateway 2.2.0
Wso2 Api Manager 3.0.0
Wso2 Enterprise Integrator 6.2.0
Wso2 Enterprise Integrator 6.3.0
Wso2 Api Manager Analytics 2.2.0
Wso2 Api Manager Analytics 2.5.0
Wso2 Identity Server 5.5.0
Wso2 Identity Server Analytics 5.5.0
Wso2 Data Analytics Server 3.2.0
Wso2 Identity Server As Key Manager 5.5.0
Wso2 Api Manager 2.2.0
Wso2 Api Manager 3.1.0
Wso2 Micro Integrator 1.0.0
Wso2 Identity Server Analytics 5.6.0
Wso2 Identity Server As Key Manager 5.6.0
Wso2 Identity Server As Key Manager 5.9.0
Wso2 Identity Server As Key Manager 5.10.0
Wso2 Api Manager Analytics 2.6.0
1 Github repository
8.8
CVSSv3
CVE-2021-44519
In Citrix XenMobile Server up to and including 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
Citrix Xenmobile Server 10.13.0
Citrix Xenmobile Server 10.14.0
2.7
CVSSv3
CVE-2022-27506
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
Citrix Sd-wan 110 Firmware
Citrix Sd-wan 210 Firmware
Citrix Sd-wan 400 Firmware
Citrix Sd-wan 410 Firmware
Citrix Sd-wan 1000 Firmware
Citrix Sd-wan 2000 Firmware
Citrix Sd-wan 2100 Firmware
Citrix Sd-wan 4000 Firmware
Citrix Sd-wan 4100 Firmware
Citrix Sd-wan 5100 Firmware
Citrix Sd-wan 6100 Firmware
Citrix Sd-wan 1100 Firmware
Citrix Sd-wan Center Management Console
Citrix Sd-wan Orchestrator
7.2
CVSSv3
CVE-2022-26151
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
Citrix Xenmobile Server 10.13.0
Citrix Xenmobile Server 10.14.0
8.8
CVSSv3
CVE-2021-44520
In Citrix XenMobile Server up to and including 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
Citrix Xenmobile Server 10.13.0
Citrix Xenmobile Server 10.14.0
7.5
CVSSv3
CVE-2022-27667
Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an malicious user to access information which would otherwise be restricted, leading to Information Disclosure.
Sap Businessobjects Business Intelligence Platform 430
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »