Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2021-25932
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site S...
Opennms Meridian
Opennms Opennms
7.8
CVSSv3
CVE-2017-11029
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer, which resides ...
Google Android -
4.8
CVSSv3
CVE-2021-25933
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site S...
Opennms Meridian
Opennms Horizon
5.4
CVSSv3
CVE-2021-25935
In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scr...
Opennms Horizon
Opennms Meridian
6.1
CVSSv3
CVE-2021-25938
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it mo...
Arangodb Arangodb
8
CVSSv3
CVE-2021-25940
In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within t...
Arangodb Arangodb
9.8
CVSSv3
CVE-2021-25941
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 up to and including 1.0.1 allows an malicious user to cause a denial of service and may lead to remote code execution.
Deep-override Project Deep-override
9.8
CVSSv3
CVE-2021-25943
Prototype pollution vulnerability in '101' versions 1.0.0 up to and including 1.6.3 allows an malicious user to cause a denial of service and may lead to remote code execution.
101 Project 101
9.8
CVSSv3
CVE-2021-25944
Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 up to and including 1.0.5 allows malicious user to cause a denial of service and may lead to remote code execution.
Deep-defaults Project Deep-defaults
9.8
CVSSv3
CVE-2021-25946
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 up to and including 0.0.2 allows an malicious user to cause a denial of service and may lead to remote code execution.
Nconf-toml Project Nconf-toml
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »