Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arbitrary vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-2725
The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote malicious users to overwrite arbitrary files via the SaveToFile function.
Db Soft Lab Dewizardx
1 EDB exploit
7.5
CVSSv2
CVE-2009-3949
cp/profile.php in VivaPrograms Infinity 2.0.5 and previous versions does not require administrative authentication for the donewauthor action, which allows remote malicious users to create administrative accounts via the name, password, and conf_password parameters.
Vivaprograms Infinity Script
Vivaprograms Infinity Script 2.0.0
1 EDB exploit
4.3
CVSSv2
CVE-2007-5278
Zomplog 3.8.1 and previous versions stores potentially sensitive information under the web root with insufficient access control, which allows remote malicious users to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct reque...
Zomplog Zomplog 3.8.1
1 EDB exploit
6.8
CVSSv2
CVE-2007-5720
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote malicious users to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
Profilecms Profilecms 1.0
1 EDB exploit
4.6
CVSSv2
CVE-2005-0698
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and previous versions allows remote malicious users to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that...
Jason Hines Phpweblog 0.5
Jason Hines Phpweblog 0.5.2
Jason Hines Phpweblog 0.4.2
Jason Hines Phpweblog 0.5.1
Jason Hines Phpweblog 0.5.3
1 EDB exploit
5
CVSSv2
CVE-2006-1704
Sire 2.0 nws allows remote malicious users to upload arbitrary image files without authentication via a direct request to upload.php.
Hubert Plisson Sire 2.0
1 EDB exploit
6.4
CVSSv2
CVE-2013-5984
Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber prior to 0.830 allows remote malicious users to delete arbitrary files via a .. (dot dot) in the file parameter.
Microweber Microweber
6.8
CVSSv2
CVE-2008-2907
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the eml parameter.
Webchamado Webchamado 1.1
1 EDB exploit
7.1
CVSSv2
CVE-2008-5677
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and previous versions, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it...
Kwalbum Kwalbum 0.9.3
Kwalbum Kwalbum 0.9.2
Kwalbum Kwalbum 0.6.15
Kwalbum Kwalbum 0.6.14
Kwalbum Kwalbum 0.6.7
Kwalbum Kwalbum 0.6.6
Kwalbum Kwalbum 0.5.9
Kwalbum Kwalbum 0.5.8
Kwalbum Kwalbum 2.0.1
Kwalbum Kwalbum 2.0
Kwalbum Kwalbum 0.8.0
Kwalbum Kwalbum 0.7.1
Kwalbum Kwalbum 0.6.11
Kwalbum Kwalbum 0.6.10
Kwalbum Kwalbum 0.6.0
Kwalbum Kwalbum 0.5.12
Kwalbum Kwalbum 0.5.4
Kwalbum Kwalbum 0.5.3
Kwalbum Kwalbum 2.0.4
Kwalbum Kwalbum
Kwalbum Kwalbum 0.9.1
Kwalbum Kwalbum 0.9.0
1 EDB exploit
7.8
CVSSv2
CVE-2007-1303
Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter.
Rrdbrowse Rrdbrowse
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
7
8
9
10
NEXT »