Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kacper szurek vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2017-11152
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to write arbitrary files via the path parameter.
Synology Photo Station 6.3-2967
Synology Photo Station
1 EDB exploit
NA
CVE-2014-8799
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin prior to 2.5.4 for WordPress allows remote malicious users to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.
Dukapress Dukapress
1 EDB exploit
NA
CVE-2014-8800
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin prior to 1.5.1 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_options action.
Nextendweb Nextend Facebook Connect
1 EDB exploit
NA
CVE-2015-2218
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin prior to 2.1 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) item[name] or (2) item...
Magic Hills Wonderplugin Audio Player
1 EDB exploit
NA
CVE-2014-8810
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin prior to 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.
Wpsymposiumpro Wp Symposium
1 EDB exploit
8.8
CVSSv3
CVE-2014-9260
The basic_settings function in the download manager plugin for WordPress prior to 2.7.3 allows remote authenticated users to update every WordPress option.
Downloadmanager Download Manager
1 EDB exploit
NA
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote malicious users to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
Codologic Codoforum 2.5.1
1 EDB exploit
8.2
CVSSv3
CVE-2014-9262
The Duplicator plugin in Wordpress prior to 0.5.10 allows remote authenticated users to create and download backup files.
Snapcreek Duplicator
1 EDB exploit
NA
CVE-2015-2199
Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin prior to 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remot...
Wonderplugin Audio Player
1 EDB exploit
NA
CVE-2014-8802
The Pie Register plugin prior to 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote malicious users to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
Genetechsolutions Pie Register
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-20065
open redirect
CVE-2024-1086
path traversal
CVE-2024-29825
XXE
CVE-2024-29822
CVE-2024-20696
CVE-2024-3564
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »