Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
high-tech bridge sa vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2012-6290
SQL injection vulnerability in ImageCMS prior to 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated malicious users to execute arbitrar...
Imagecms Imagecms
1 EDB exploit
NA
CVE-2013-3515
Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) package parameter to www/admin/plugin-index.php or the (2) group parameter to www/admin/plugin-settings...
Openx Openx
Openx Openx 2.8
Openx Openx 2.4.9
Openx Openx 2.4.8
Openx Openx 2.6.4
Openx Openx 2.7.29
Openx Openx 2.6.3
Openx Openx 2.4.4
Openx Openx 2.6.1
Openx Openx 2.6.2
Openx Openx 2.8.2
Openx Openx 2.8.3
Openx Openx 2.8.1
Openx Openx 2.4
Openx Openx 2.4.11
Openx Openx 2.4.10
Openx Openx 2.8.4
Openx Openx 2.8.5
Openx Openx 2.4.5
Openx Openx 2.4.6
Openx Openx 2.4.7
Openx Openx 2.6.0
1 EDB exploit
NA
CVE-2012-4772
SQL injection vulnerability in register/ in Subrion CMS prior to 2.2.3 allows remote malicious users to execute arbitrary SQL commands via the plan_id parameter.
Intelliants Subrion Cms 2.2.1
Intelliants Subrion Cms 2.2.0
Intelliants Subrion Cms 2.0.4
Intelliants Subrion Cms
1 EDB exploit
NA
CVE-2012-4901
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to admin/index.php.
Template Cms Project Template Cms
1 EDB exploit
NA
CVE-2013-5692
Directory traversal vulnerability in X2Engine X2CRM prior to 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.
X2engine X2crm 3.0.1
X2engine X2crm 3.0
X2engine X2crm 2.9.1
X2engine X2crm 2.9
X2engine X2crm 1.2.1
X2engine X2crm 1.2.0
X2engine X2crm 1.1.0
X2engine X2crm 1.0.1
X2engine X2crm 1.0
X2engine X2crm 3.4
X2engine X2crm 3.3.2
X2engine X2crm 3.3.1
X2engine X2crm
X2engine X2crm 3.2
X2engine X2crm 3.1.1
X2engine X2crm 3.0.2
X2engine X2crm 2.8.1
X2engine X2crm 2.7.2
X2engine X2crm 1.3.1
X2engine X2crm 1.2.2
X2engine X2crm 3.3
X2engine X2crm 2.7
1 EDB exploit
7.5
CVSSv3
CVE-2015-3302
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress prior to 1.3.9.3 allows remote malicious users to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
Thecartpress Thecartpress Ecommerce Shopping Cart
1 EDB exploit
NA
CVE-2014-3414
Cross-site request forgery (CSRF) vulnerability in Sharetronix prior to 3.4 allows remote malicious users to hijack the authentication of administrators for requests that add administrative privileges to a user via the admin parameter to admin/administrators.
Sharetronix Sharetronix
1 EDB exploit
NA
CVE-2014-3415
SQL injection vulnerability in Sharetronix prior to 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group.
Sharetronix Sharetronix 3.1.1
Sharetronix Sharetronix
1 EDB exploit
NA
CVE-2013-0807
Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the section parameter in a new_section action to index.php...
Gpeasy Gpeasy Cms 1.5
Gpeasy Gpeasy Cms 1.6.1
Gpeasy Gpeasy Cms 1.6.2
Gpeasy Gpeasy Cms 2.3.2
Gpeasy Gpeasy Cms 2.3.3
Gpeasy Gpeasy Cms 2.4
Gpeasy Gpeasy Cms 3.5
Gpeasy Gpeasy Cms 3.5.1
Gpeasy Gpeasy Cms 1.6
Gpeasy Gpeasy Cms 2.3
Gpeasy Gpeasy Cms 2.3.1
Gpeasy Gpeasy Cms 3.0.4
Gpeasy Gpeasy Cms 3.0.5
Gpeasy Gpeasy Cms 1.6.3
Gpeasy Gpeasy Cms 2.0.1
Gpeasy Gpeasy Cms 3.0
Gpeasy Gpeasy Cms 3.0.1
Gpeasy Gpeasy Cms
Gpeasy Gpeasy Cms 2.1
Gpeasy Gpeasy Cms 2.2
Gpeasy Gpeasy Cms 3.0.2
Gpeasy Gpeasy Cms 3.0.3
1 EDB exploit
NA
CVE-2013-6839
SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the orderby parameter to catalog/[id].
Instantsoft Instantcms
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »