Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ultimate vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-34208
Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and previous versions allow remote authenticated users to extract files into arbitrary directories via a crafted ZIP archive.
Easyuse Mailhunter Ultimate
NA
CVE-2023-34209
Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHunter Ultimate 2023 and previous versions allow remote authenticated users to obtain the absolute path via unencrypted VIEWSTATE parameter.
Easyuse Mailhunter Ultimate
NA
CVE-2023-34210
SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and previous versions allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL parameter.
Easyuse Mailhunter Ultimate
4.3
CVSSv2
CVE-2016-10872
The ultimate-member plugin prior to 1.3.40 for WordPress has XSS on the login form.
Ultimatemember Ultimate Member
4.3
CVSSv2
CVE-2020-7107
The Ultimate FAQ plugin prior to 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
Etoilewebdesign Ultimate Faq
4
CVSSv2
CVE-2017-2245
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote malicious users to read arbitrary files via unspecified vectors.
Getshortcodes Shortcodes Ultimate
5
CVSSv2
CVE-2020-36170
The Ultimate Member plugin prior to 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
Ultimatemember Ultimate Member
4.3
CVSSv2
CVE-2018-13136
The Ultimate Member (aka ultimatemember) plugin prior to 2.0.18 for WordPress has XSS via the wp-admin settings screen.
Ultimatemember Ultimate Member
6.4
CVSSv2
CVE-2017-9625
An Improper Authentication issue exists in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an malicious user to view information and modify settings or execute code remotely.
Envitech Envidas Ultimate
4.3
CVSSv2
CVE-2018-20965
The ultimate-member plugin prior to 2.0.4 for WordPress has XSS.
Ultimatemember Ultimate Member
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »