Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
coldfusion vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2011-0583
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 up to and including 9.0.1 allows remote malicious users to inject arbitrary web script or HTML via the cfform tag.
Adobe Coldfusion 8.0.1
Adobe Coldfusion 9.0
Adobe Coldfusion 8.0
Adobe Coldfusion 9.0.1
605
VMScore
CVE-2011-0629
Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Adobe Coldfusion 9.0
Adobe Coldfusion 9.0.1
Adobe Coldfusion 8.0
Adobe Coldfusion 8.0.1
755
VMScore
CVE-1999-0477
The Expression Evaluator in the ColdFusion Application Server allows a remote malicious user to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
Allaire Coldfusion Server 2.0
Allaire Coldfusion Server 3.0
Allaire Coldfusion Server 3.01
Allaire Coldfusion Server 3.11
Allaire Coldfusion Server 3.12
Allaire Coldfusion Server 4.0
1 EDB exploit
NA
CVE-2023-44350
Adobe ColdFusion versions 2023.5 (and previous versions) and 2021.11 (and previous versions) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Adobe Coldfusion 2021
Adobe Coldfusion 2023
Adobe Coldfusion
NA
CVE-2023-44351
Adobe ColdFusion versions 2023.5 (and previous versions) and 2021.11 (and previous versions) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Adobe Coldfusion 2021
Adobe Coldfusion 2023
Adobe Coldfusion
NA
CVE-2023-44352
Adobe ColdFusion versions 2023.5 (and previous versions) and 2021.11 (and previous versions) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious J...
Adobe Coldfusion 2021
Adobe Coldfusion 2023
Adobe Coldfusion
NA
CVE-2023-44353
Adobe ColdFusion versions 2023.5 (and previous versions) and 2021.11 (and previous versions) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Adobe Coldfusion 2021
Adobe Coldfusion 2023
Adobe Coldfusion
NA
CVE-2023-44355
Adobe ColdFusion versions 2023.5 (and previous versions) and 2021.11 (and previous versions) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to impact a minor ...
Adobe Coldfusion 2021
Adobe Coldfusion 2023
Adobe Coldfusion
NA
CVE-2023-29298
Adobe ColdFusion versions 2018u16 (and previous versions), 2021u6 (and previous versions) and 2023.0.0.330468 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabi...
Adobe Coldfusion 2018
Adobe Coldfusion 2021
Adobe Coldfusion
NA
CVE-2023-29300
Adobe ColdFusion versions 2018u16 (and previous versions), 2021u6 (and previous versions) and 2023.0.0.330468 (and previous versions) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does n...
Adobe Coldfusion 2018
Adobe Coldfusion 2021
Adobe Coldfusion
3 Github repositories
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »