Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-36774
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows malicious users to execute arbitrary code via uploading a crafted PHP file.
NA
CVE-2024-36775
A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.
NA
CVE-2024-36823
The encrypt() function of Ninja Core v7.0.0 exists to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.
NA
CVE-2024-4013
A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity ...
NA
CVE-2024-24194
robdns commit d76d2e6 exists to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.
NA
CVE-2023-49441
dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.
NA
CVE-2024-22525
dnspod-sr 0dfbd37 contains a SEGV.
NA
CVE-2024-22074
Dynamsoft Service 1.8.1025 up to and including 1.8.2013, 1.7.0330 up to and including 1.7.2531, 1.6.0428 up to and including 1.6.1112, 1.5.0625 up to and including 1.5.3116, 1.4.0618 up to and including 1.4.1230, and 1.0.516 up to and including 1.3.0115 has Incorrect Access Contr...
NA
CVE-2024-36795
Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows malicious users to access URLs and directories embedded within the firmware via unspecified vectors.
NA
CVE-2024-4851
A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows malicious users to access internal networks. The vulnerability is present in the crawl endpoint where the 'url' parameter can be manipulated to s...
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »