Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
admin vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-0648
A vulnerability, which was classified as critical, was found in dst-admin 1.5.0. This affects an unknown part of the file /home/masterConsole. The manipulation of the argument command leads to command injection. It is possible to initiate the attack remotely. The exploit has been...
Dst-admin Project Dst-admin 1.5.0
5.8
CVSSv2
CVE-2018-11092
An issue exists in the Admin Notes plugin 1.1 for MyBB. CSRF allows an malicious user to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.
Admin Notes Project Admin Notes 1.1
NA
CVE-2023-0647
A vulnerability, which was classified as critical, has been found in dst-admin 1.5.0. Affected by this issue is some unknown functionality of the file /home/kickPlayer. The manipulation of the argument userId leads to command injection. The attack may be launched remotely. The ex...
Dst-admin Project Dst-admin 1.5.0
NA
CVE-2023-0649
A vulnerability has been found in dst-admin 1.5.0 and classified as critical. This vulnerability affects unknown code of the file /home/sendBroadcast. The manipulation of the argument message leads to command injection. The attack can be initiated remotely. The exploit has been d...
Dst-admin Project Dst-admin 1.5.0
4.3
CVSSv2
CVE-2022-1599
The Admin Management Xtended WordPress plugin prior to 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing malicious users to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post dat...
Admin Management Xtended Project Admin Management Xtended
4.3
CVSSv2
CVE-2016-1000126
Reflected XSS in wordpress plugin admin-font-editor v1.8
Admin-font-editor Project Admin-font-editor
6.5
CVSSv2
CVE-2022-24844
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. The problem occurs in the following code in server/service/system/sys_auto_code_pgsql.go, which means that PostgreSQL must be used as the database for this v...
Gin-vue-admin Project Gin-vue-admin
6.8
CVSSv2
CVE-2022-29450
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
Admin Management Xtended Project Admin Management Xtended
NA
CVE-2023-24007
Cross-Site Request Forgery (CSRF) vulnerability in TheOnlineHero - Tom Skroza Admin Block Country plugin <= 7.1.4 versions.
Admin Block Country Project Admin Block Country
6.8
CVSSv2
CVE-2017-12881
Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin prior to 1.3.0 allows remote malicious users to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerability.
Spring Batch Admin Project Spring Batch Admin
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »