Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
felix vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2016-3694
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote malicious users to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/e...
Modified Ecommerce Shopsoftware 2.0.0.0
1 EDB exploit
NA
CVE-2010-4335
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x up to and including 1.3.5 and 1.2.8 allows remote malicious users to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the ...
Cakefoundation Cakephp 1.3.0
Cakefoundation Cakephp 1.3.4
Cakefoundation Cakephp 1.3.5
Cakefoundation Cakephp 1.2.8
Cakefoundation Cakephp 1.3.2
Cakefoundation Cakephp 1.3.3
Cakefoundation Cakephp 1.3
Cakefoundation Cakephp 1.3.1
2 EDB exploits
NA
CVE-2007-6602
SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and previous versions allows remote malicious users to execute arbitrary SQL commands via the username field to the login script.
Noserub Noserub
1 EDB exploit
9.1
CVSSv3
CVE-2020-12676
FusionAuth fusionauth-samlv2 0.2.3 allows remote malicious users to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".
Fusionauth Samlv2 0.2.3
2 Github repositories
NA
CVE-2020-126762020
Unauthenticated users can send forged messages to the FusionAuth to bypass authentication, impersonate other users or gain arbitrary roles. The SAML message can be send to the application without a signature even if this is required. The impact depends on individual applications ...
6.7
CVSSv3
CVE-2022-21499
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Scor...
Oracle Linux 6
Oracle Linux 7
Oracle Linux 8
Debian Debian Linux 11.0
1 Github repository
4.1
CVSSv3
CVE-2022-1974
A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information.
Linux Linux Kernel 5.18
5.5
CVSSv3
CVE-2022-1975
There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an malicious user to crash the Linux kernel by simulating a nfc device from user-space.
Linux Linux Kernel 5.18
NA
CVE-2008-0533
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) prior to 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote malicious users to inject arbitrary web script or HTML vi...
Cisco Acs Solution Engine
Cisco User Changeable Password 4.1
Cisco Acs For Windows
1 EDB exploit
NA
CVE-2008-0532
Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) prior to 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote malicious users to execute arbitrary code via a long argument located immediately a...
Cisco Acs Solution Engine
Cisco User Changeable Password 4.1
Cisco Acs For Windows
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
NEXT »