Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zend zend framework vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2014-4914
The Zend_Db_Select::order function in Zend Framework prior to 1.12.7 does not properly handle parentheses, which allows remote malicious users to conduct SQL injection attacks via unspecified vectors.
Zend Zend Framework
Debian Debian Linux 8.0
Debian Debian Linux 7.0
7.5
CVSSv3
CVE-2015-7503
Zend Framework prior to 2.4.9, zend-framework/zend-crypt 2.4.x prior to 2.4.9, and 2.5.x prior to 2.5.2 allows remote malicious users to recover the RSA private key.
Zend Zend Framework 2.4.3
Zend Zend Framework 2.4.5
Zend Zend Framework 2.4.1
Zend Zend Framework 2.4.4
Zend Zend Framework 2.5.1
Zend Zend Framework 2.4.2
Zend Zend Framework 2.5.0
Zend Zend Framework 2.4.0
Zend Zend Framework 2.4.8
Zend Zend Framework 2.4.7
Zend Zend Framework 2.4.6
9.1
CVSSv3
CVE-2015-1555
Zend/Session/SessionManager in Zend Framework 2.2.x prior to 2.2.9, 2.3.x prior to 2.3.4 allows remote malicious users to create valid sessions without using session validators.
Zend Zend Framework 2.2.4
Zend Zend Framework 2.3.0
Zend Zend Framework 2.2.1
Zend Zend Framework 2.2.2
Zend Zend Framework 2.2.8
Zend Zend Framework 2.2.7
Zend Zend Framework 2.3.1
Zend Zend Framework 2.3.2
Zend Zend Framework 2.3.3
Zend Zend Framework 2.2.3
Zend Zend Framework 2.2.0
Zend Zend Framework 2.2.6
Zend Zend Framework 2.2.5
8.8
CVSSv3
CVE-2015-1786
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x prior to 2.3.6 via null or malformed token identifiers.
Zend Zend Framework 2.3.0
Zend Zend Framework 2.3.4
Zend Zend Framework 2.3.1
Zend Zend Framework 2.3.2
Zend Zend Framework 2.3.3
Zend Zend Framework 2.3.5
9.8
CVSSv3
CVE-2016-4861
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework prior to 1.12.20 might allow remote malicious users to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
Fedoraproject Fedora 25
Fedoraproject Fedora 24
Fedoraproject Fedora 23
Zend Zend Framework
9.8
CVSSv3
CVE-2016-6233
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework prior to 1.12.19 might allow remote malicious users to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
Fedoraproject Fedora 25
Fedoraproject Fedora 24
Fedoraproject Fedora 23
Zend Zend Framework
9.8
CVSSv3
CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer prior to 5.2.18 might allow remote malicious users to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Phpmailer Project Phpmailer
Wordpress Wordpress
Joomla Joomla!
9 EDB exploits
121 Github repositories
9.8
CVSSv3
CVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component prior to 2.4.11, 2.5.x, 2.6.x, and 2.7.x prior to 2.7.2, and Zend Framework prior to 2.4.11 might allow remote malicious users to pass extra parameters to the mail command and consequently execute arbitrary c...
Zend Zend Framework
Zend Zend-mail 2.6.2
Zend Zend-mail 2.5.2
Zend Zend-mail 2.5.0
Zend Zend-mail
Zend Zend-mail 2.6.0
Zend Zend-mail 2.7.0
Zend Zend-mail 2.6.1
Zend Zend-mail 2.7.1
Zend Zend-mail 2.5.1
3 EDB exploits
3 Github repositories
9.8
CVSSv3
CVE-2016-10045
The isMail transport in PHPMailer prior to 5.2.20 might allow remote malicious users to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the ...
Phpmailer Project Phpmailer
Wordpress Wordpress
Joomla Joomla!
3 EDB exploits
92 Github repositories
9.8
CVSSv3
CVE-2016-10074
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer prior to 5.4.5 might allow remote malicious users to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the ...
Swiftmailer Swiftmailer
3 EDB exploits
3 Github repositories
1 Article
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »