Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hyp3rlinx.altervista.org vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2018-18552
ServersCheck Monitoring Software up to and including 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes...
Serverscheck Monitoring Software
5.7
CVSSv3
CVE-2016-5537
Unspecified vulnerability in the NetBeans component in Oracle Fusion Middleware 8.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the October 2016 CPU. Oracle has not commented on third-party ...
Oracle Netbeans 8.1
6.1
CVSSv3
CVE-2016-5715
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter. NOTE: thi...
Puppet Puppet Enterprise
6.1
CVSSv3
CVE-2018-6361
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
Ehcp Easy Hosting Control Panel 0.37.12.b
6.1
CVSSv3
CVE-2018-6362
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
Ehcp Easy Hosting Control Panel 0.37.12.b
8.8
CVSSv3
CVE-2018-6458
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote malicious users to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
Ehcp Easy Hosting Control Panel 0.37.12.b
6.1
CVSSv3
CVE-2016-2078
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote malicious users to inject arbitrary web script or HTML via the flashvars parameter.
Vmware Vcenter Server 6.0
Vmware Vcenter Server 5.5
Vmware Vcenter Server 5.1
Vmware Vcenter Server 5.0
7.3
CVSSv3
CVE-2017-9046
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a mailto: link on a remote w...
Pmail Pegasus 4.72
NA
CVE-2015-2872
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software prior to 3.5.1477, 3.6.x prior to 3.6.1217, 3.7.x prior to 3.7.1248, 3.8.x prior to 3.8.1263, and other versions allow remote malici...
Trendmicro Deep Discovery Inspector 3.5
Trendmicro Deep Discovery Inspector 3.6
Trendmicro Deep Discovery Inspector 3.7
Trendmicro Deep Discovery Inspector 3.8
NA
CVE-2015-2873
Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software prior to 3.5.1477, 3.6.x prior to 3.6.1217, 3.7.x prior to 3.7.1248, 3.8.x prior to 3.8.1263, and other versions allows remote malicious users to obtain sensitive information or change th...
Trendmicro Deep Discovery Inspector 3.5
Trendmicro Deep Discovery Inspector 3.6
Trendmicro Deep Discovery Inspector 3.7
Trendmicro Deep Discovery Inspector 3.8
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »