Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
application server vulnerabilities and exploits
(subscribe to this query)
9.9
CVSSv3
CVE-2020-1210
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint applicati...
Microsoft Sharepoint Foundation 2010
Microsoft Sharepoint Foundation 2013
Microsoft Sharepoint Enterprise Server 2016
Microsoft Sharepoint Enterprise Server 2013
Microsoft Sharepoint Server 2019
1 Article
9.9
CVSSv3
CVE-2020-15860
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published....
Parallels Remote Application Server 17.1.1
9.8
CVSSv3
CVE-2022-32257
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to...
Siemens Sinema Remote Connect Server
9.8
CVSSv3
CVE-2024-23822
Thruk is a multibackend monitoring webinterface. before 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form that allows a threat actor to arbitrarily upload files to the server to any path they desire and have permissions for. This vulnerabil...
Thruk Thruk
9.8
CVSSv3
CVE-2024-0510
A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of the file /application/pay/controller/Api.php. The manipulation of the argument url leads to server-side request forgery. The attac...
Haokekeji Yiqiniu
9.8
CVSSv3
CVE-2024-0352
A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the argument...
Likeshop Likeshop
9.8
CVSSv3
CVE-2023-49091
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the authorization header used for user login remaining valid and not expiring after log out. This vulner...
Cosmos-cloud Cosmos Server 0.1.15
Cosmos-cloud Cosmos Server 0.1.16
Cosmos-cloud Cosmos Server 0.1.17
Cosmos-cloud Cosmos Server 0.2.0
Cosmos-cloud Cosmos Server 0.3.0
Cosmos-cloud Cosmos Server 0.3.1
Cosmos-cloud Cosmos Server 0.3.2
Cosmos-cloud Cosmos Server 0.3.3
Cosmos-cloud Cosmos Server 0.3.4
Cosmos-cloud Cosmos Server 0.3.5
Cosmos-cloud Cosmos Server 0.4.0
Cosmos-cloud Cosmos Server 0.4.1
Cosmos-cloud Cosmos Server 0.4.2
Cosmos-cloud Cosmos Server 0.4.3
Cosmos-cloud Cosmos Server 0.5.0
Cosmos-cloud Cosmos Server 0.5.1
Cosmos-cloud Cosmos Server 0.5.2
Cosmos-cloud Cosmos Server 0.5.3
Cosmos-cloud Cosmos Server 0.5.4
Cosmos-cloud Cosmos Server 0.5.5
Cosmos-cloud Cosmos Server 0.5.6
Cosmos-cloud Cosmos Server 0.5.7
9.8
CVSSv3
CVE-2023-46302
Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail/CVE-2022-1471 . Apache Submarine uses JAXRS to define REST endpoints. In order to handle YAML requests (using application/yaml cont...
Apache Submarine
9.8
CVSSv3
CVE-2023-46850
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
Openvpn Openvpn
Openvpn Openvpn Access Server
Debian Debian Linux 12.0
Fedoraproject Fedora 39
9.8
CVSSv3
CVE-2023-46158
IBM WebSphere Application Server Liberty 23.0.0.9 up to and including 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
Ibm Websphere Application Server Liberty
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »