Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
owasp vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-29577
OWASP AntiSamy prior to 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.
Antisamy Project Antisamy
Oracle Weblogic Server 12.2.1.3.0
Oracle Weblogic Server 12.2.1.4.0
Oracle Weblogic Server 14.1.1.0.0
Oracle Enterprise Manager Base Platform 13.4.0.0
Oracle Enterprise Manager Base Platform 13.5.0.0
9.8
CVSSv3
CVE-2020-10683
dom4j prior to 2.0.3 and 2.1.x prior to 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j...
Dom4j Project Dom4j
Oracle Insurance Policy Administration J2ee 10.2.0
Oracle Insurance Rules Palette 10.2.0
Oracle Retail Integration Bus 15.0
Oracle Webcenter Portal 12.2.1.3.0
Oracle Webcenter Portal 11.1.1.9.0
Oracle Utilities Framework 4.2.0.3.0
Oracle Utilities Framework 4.2.0.2.0
Oracle Utilities Framework 2.2.0.0.0
Oracle Flexcube Core Banking 11.7.0
Oracle Business Process Management Suite 12.2.1.3.0
Oracle Endeca Information Discovery Integrator 3.2.0
Oracle Application Testing Suite 13.3.0.1
Oracle Retail Order Broker 15.0
Oracle Retail Order Broker 16.0
Oracle Retail Integration Bus 16.0
Oracle Retail Customer Management And Segmentation Foundation 16.0
Oracle Retail Customer Management And Segmentation Foundation 17.0
Oracle Retail Customer Management And Segmentation Foundation 18.0
Oracle Enterprise Data Quality 12.2.1.3.0
Oracle Data Integrator 12.2.1.3.0
Oracle Utilities Framework 4.4.0.0.0
7.5
CVSSv3
CVE-2023-40586
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious reques...
Coraza Coraza 3.0.0
7.5
CVSSv3
CVE-2022-28366
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko up to and including 2.26, and is fixed in 2.27. This issue also exists in Cyb...
Cyberneko Html Project Cyberneko Html
Htmlunit Htmlunit
Antisamy Project Antisamy
1 Github repository
7.5
CVSSv3
CVE-2022-34770
Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specific restaurant, alcohol consumption and smoking habits. Each of the described API’s, has in its...
Tabit Tabit
7.5
CVSSv3
CVE-2022-34775
Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. This can be used to query the http://tgm-api.tabit.cloud/rsv/management/{reservationId}?organization={or...
Tabit Tabit
8.8
CVSSv3
CVE-2021-41171
eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW prior to 4.1.0, it allows malicious users to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Cookie header. This issue has been a...
Elabftw Elabftw
NA
CVE-2015-6032
Qolsys IQ Panel (aka QOL) prior to 1.5.1 has hardcoded cryptographic keys, which allows remote malicious users to create digital signatures for code by leveraging knowledge of a key from a different installation.
Qolsys Iq Panel
NA
CVE-2015-6033
Qolsys IQ Panel (aka QOL) prior to 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle malicious users to bypass intended access restrictions via a modified update.
Qolsys Iq Panel
6.1
CVSSv3
CVE-2016-6436
Cross-site scripting (XSS) vulnerability in HostScan Engine 3.0.08062 up to and including 3.1.14018 in the Cisco Host Scan package, as used in ASA Web VPN, allows remote malicious users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz14682.
Cisco Hostscan Engine 3.1.05152
Cisco Hostscan Engine 3.1.14018
Cisco Hostscan Engine 3.1.03104
Cisco Hostscan Engine 3.1.02026
Cisco Hostscan Engine 3.1.05182
Cisco Hostscan Engine 3.1.04075
Cisco Hostscan Engine 3.1.04082
Cisco Hostscan Engine 3.1.06073
Cisco Hostscan Engine 3.1.03103
Cisco Hostscan Engine 3.0.08062
Cisco Hostscan Engine 3.1.05183
Cisco Hostscan Engine 3.1.05178
Cisco Hostscan Engine 3.1.02043
Cisco Hostscan Engine 3.0.08066
Cisco Hostscan Engine 3.1.05163
Cisco Hostscan Engine 3.1.01065
Cisco Hostscan Engine 3.1.04060
Cisco Hostscan Engine 3.1.02016
Cisco Hostscan Engine 3.1.04063
Cisco Hostscan Engine 3.1.05170
Cisco Hostscan Engine 3.1.02040
Cisco Hostscan Engine 3.1.05160
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »