Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
shell vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-2280
Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) prior to 4.3.4 allows remote malicious users to inject arbitrary web script or HTML via the query parameter.
Seeddms Seeddms
Seeddms Seeddms 3.4.3
Seeddms Seeddms 3.3.12
7.2
CVSSv3
CVE-2017-15673
The files function in the administration section in CS-Cart 4.6.2 and previous versions allows malicious users to execute arbitrary PHP code via vectors involving a custom page.
Cs-cart Cs-cart
1 Github repository
8.8
CVSSv3
CVE-2021-3164
ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php.
Churchdesk Churchrota 2.6.4
1 Github repository
NA
CVE-2007-2430
shared/code/tce_tmx.php in TCExam 4.0.011 and previous versions allows remote malicious users to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.
Tecnick.com Tcexam
1 EDB exploit
NA
CVE-2024-36472
In GNOME Shell up to and including 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, whic...
8.8
CVSSv3
CVE-2017-9380
OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.
Open-emr Openemr
7.2
CVSSv3
CVE-2020-36079
Zenphoto up to and including 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, f...
Zenphoto Zenphoto
1 Github repository
NA
CVE-2013-6226
Directory traversal vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) prior to 5.0.4 allows remote malicious users to read or delete arbitrary files via unspecified vectors.
Ajaxplorer Ajaxplorer 3.1.1
Ajaxplorer Ajaxplorer 2.5
Ajaxplorer Ajaxplorer 3.3.2
Ajaxplorer Ajaxplorer 3.0.1
Ajaxplorer Ajaxplorer 4.2.3
Ajaxplorer Ajaxplorer 4.0.4
Ajaxplorer Ajaxplorer 3.3.4
Ajaxplorer Ajaxplorer 5.0.1
Ajaxplorer Ajaxplorer 3.0
Ajaxplorer Ajaxplorer 2.7.2
Ajaxplorer Ajaxplorer 3.1
Ajaxplorer Ajaxplorer 3.2.3
Ajaxplorer Ajaxplorer 2.6.0
Ajaxplorer Ajaxplorer 2.5.4
Ajaxplorer Ajaxplorer 4.2.2
Ajaxplorer Ajaxplorer 2.3.3
Ajaxplorer Ajaxplorer 5.0.2
Ajaxplorer Ajaxplorer 3.2.1
Ajaxplorer Ajaxplorer 3.2.5
Ajaxplorer Ajaxplorer
Ajaxplorer Ajaxplorer 4.0.3
Ajaxplorer Ajaxplorer 2.3.4
7.2
CVSSv3
CVE-2022-26965
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
Pluck-cms Pluck 4.7.16
3 Github repositories
8.8
CVSSv3
CVE-2020-28687
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote malicious users to upload arbitrary files.
Artworks Gallery In Php, Css, Javascript, And Mysql Project Artworks Gallery In Php, Css, Javascript, And Mysql 1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37884
CVE-2024-6003
remote
brute force
information disclosure
CVE-2024-27801
CVE-2024-30078
CVE-2024-31870
CVE-2024-6042
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »