Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
web project web vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-4171
calibre-web is vulnerable to Business Logic Errors
Calibre-web Project Calibre-web
9.8
CVSSv3
CVE-2022-46478
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows malicious users to execute arbitrary commands via crafted Hessian serialized data.
Datax-web Project Datax-web
1 Github repository
7.5
CVSSv3
CVE-2015-5236
It exists that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass...
Icedtea-web Project Icedtea-web -
9.8
CVSSv3
CVE-2023-2106
Weak Password Requirements in GitHub repository janeczku/calibre-web before 0.6.20.
Calibre-web Project Calibre-web
9.9
CVSSv3
CVE-2022-0767
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web before 0.6.17.
Calibre-web Project Calibre-web
5.4
CVSSv3
CVE-2021-25964
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS wil...
Calibre-web Project Calibre-web
9.9
CVSSv3
CVE-2022-0939
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web before 0.6.18.
Calibre-web Project Calibre-web
7.2
CVSSv3
CVE-2022-4372
The Web Invoice WordPress plugin up to and including 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration...
Web Invoice Project Web Invoice
5.4
CVSSv3
CVE-2021-4170
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Calibre-web Project Calibre-web
NA
CVE-2007-5598
Cross-site scripting (XSS) vulnerability in Weblinks for Drupal 4.7.x prior to 4.7.x-1.0 and 5.x prior to 5.x-1.8 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Web Links Project Web Links
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »