Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
core security technologies vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2018-107123
ASRock offers several utilities designed to give the user with an ASRock motherboard more control over certain settings and functions. These utilities include various features like the RGB LED control, hardware monitor, fan controls, and overclocking/voltage options. Multiple vul...
7.8
CVSSv3
CVE-2018-15442
A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local malicious user to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacke...
Cisco Webex Meetings Desktop
Cisco Webex Productivity Tools
2 EDB exploits
1 Nmap script
9.8
CVSSv3
CVE-2018-17440
An issue exists on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by upl...
Dlink Central Wifimanager
1 EDB exploit
6.1
CVSSv3
CVE-2018-17441
An issue exists on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.
Dlink Central Wifimanager
1 EDB exploit
6.1
CVSSv3
CVE-2018-17443
An issue exists on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.
Dlink Central Wifimanager
1 EDB exploit
8.8
CVSSv3
CVE-2018-17442
An issue exists on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.
Dlink Central Wifimanager
1 EDB exploit
NA
CVE-2018-174413
D-Link Central WiFiManager Software Controller suffers from hard-coded credential, code execution, and cross site scripting vulnerabilities. Version 1.03 is affected.
8.1
CVSSv3
CVE-2018-16145
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor prior to 5.3.1 and 5.4.x prior to 5.4.2 invokes a file that can be edited by the nagios user, and would allow malicious users to elevate their privileges to root after a system restart, henc...
Opsview Opsview
6.1
CVSSv3
CVE-2018-16148
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor prior to 5.3.1 and 5.4.x prior to 5.4.2 is vulnerable to Cross-Site Scripting.
Opsview Opsview
6.1
CVSSv3
CVE-2018-16147
The data parameter of the /settings/api/router endpoint in Opsview Monitor prior to 5.3.1 and 5.4.x prior to 5.4.2 is vulnerable to Cross-Site Scripting.
Opsview Opsview
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »