Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
daniel correa vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2012-4070
SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote malicious users to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.
Dir2web Dir2web 3.0
1 EDB exploit
6.1
CVSSv3
CVE-2017-11355
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) p...
Pega Pega Platform
1 EDB exploit
6.5
CVSSv3
CVE-2017-11356
The application distribution export functionality in PEGA Platform 7.2 ML0 and previous versions allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.
Pega Pega Platform
1 EDB exploit
NA
CVE-2012-4069
Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download the database via a direct request for system/db/website.db.
Dir2web Dir2web 3.0
9.8
CVSSv3
CVE-2017-13771
Lexmark Scan To Network (SNF) 3.2.9 and previous versions stores network configuration credentials in plaintext and transmits them in requests, which allows remote malicious users to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestSe...
Lexmark Scan To Network
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started