Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
configuration manager vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users'...
Manageengine Applications Manager 12.0
Manageengine Applications Manager 13.0
9.8
CVSSv3
CVE-2018-6491
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
Microfocus Ucmdb Configuration Manager 10.20
Microfocus Ucmdb Configuration Manager 10.21
Microfocus Ucmdb Configuration Manager 10.22
Microfocus Ucmdb Configuration Manager 10.30
Microfocus Ucmdb Configuration Manager 10.31
Microfocus Ucmdb Configuration Manager 10.32
Microfocus Ucmdb Configuration Manager 10.33
Microfocus Ucmdb Configuration Manager 11.00
9.8
CVSSv3
CVE-2018-8733
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x up to and including 5.4.x prior to 5.4.13 allows an unauthenticated malicious user to make configuration changes and leverage an authenticated SQL injection vulnerability.
Nagios Nagios Xi
2 EDB exploits
1 Github repository
9.8
CVSSv3
CVE-2018-1217
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated malicious user to read ...
Dell Emc Avamar 7.5.0
Dell Emc Integrated Data Protection Appliance 2.0
Dell Emc Integrated Data Protection Appliance 2.1
Dell Emc Avamar 7.3.1
Dell Emc Avamar 7.4.1
1 EDB exploit
9.8
CVSSv3
CVE-2018-6488
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.
Microfocus Ucmdb Configuration Manager 4.10
Microfocus Ucmdb Configuration Manager 4.11
Microfocus Ucmdb Configuration Manager 4.12
9.8
CVSSv3
CVE-2018-0124
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote malicious user to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is due to insecure key generation during application config...
Cisco Unified Communications Domain Manager
2 Github repositories
9.8
CVSSv3
CVE-2017-8947
A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.
Hp Ucmdb Configuration Manager 10.20
Hp Ucmdb Configuration Manager 10.22
Hp Ucmdb Configuration Manager 10.30
Hp Ucmdb Configuration Manager 10.31
Hp Ucmdb Configuration Manager 10.10
Hp Ucmdb Configuration Manager 10.11
Hp Ucmdb Configuration Manager 10.21
9.8
CVSSv3
CVE-2011-4889
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 prior to 6.1.0.43, 7.0 prior to 7.0.0.21, and 8.0 prior to 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Ser...
Ibm Websphere Application Server
9.8
CVSSv3
CVE-2017-14351
A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow code execution.
Hp Ucmdb Configuration Manager 10.10
Hp Ucmdb Configuration Manager 10.11
Hp Ucmdb Configuration Manager 10.20
Hp Ucmdb Configuration Manager 10.21
Hp Ucmdb Configuration Manager 10.22
Hp Ucmdb Configuration Manager 10.23
9.8
CVSSv3
CVE-2015-7705
The rate limiting feature in NTP 4.x prior to 4.2.8p4 and 4.3.x prior to 4.3.77 allows remote malicious users to have unspecified impact via a large number of crafted requests.
Ntp Ntp
Ntp Ntp 4.2.8
Netapp Oncommand Performance Manager -
Netapp Oncommand Unified Manager -
Netapp Clustered Data Ontap -
Netapp Data Ontap -
Citrix Xenserver 6.0.2
Citrix Xenserver 6.2.0
Citrix Xenserver 6.5
Citrix Xenserver 7.0
Siemens Tim 4r-ie Firmware
Siemens Tim 4r-ie Dnp3 Firmware
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »