Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
craig vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2013-6026
The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote malicious users to bypass authentication and modify settings via an xmlset_r...
Dlink Di-604s -
Dlink Tm-g5240 -
Dlink Di-524up -
Dlink Di-604up -
Dlink Di-624s -
Dlink Di-604+ -
Dlink Dir-120 -
Dlink Dir-100 -
Alphanetworks Vdsl Asl-55052 -
Alphanetworks Vdsl Asl-56552 -
Planex Brl-04r -
Planex Brl-04cw -
Planex Brl-04ur -
2 Github repositories
10
CVSSv2
CVE-2006-7134
Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote malicious users to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely fro...
Noah Spurrier Upload Tool For Php 1.0
1 EDB exploit
10
CVSSv2
CVE-2007-1225
The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote malicious users to conduct unauthorized activities and avoid detection.
Grok Developments Netproxy 4.03
1 EDB exploit
10
CVSSv2
CVE-2000-0253
The dansie shopping cart application cart.pl allows remote malicious users to modify sensitive purchase information via hidden form fields.
Craig Dansie Dansie Shopping Cart 3.0.4
9.3
CVSSv2
CVE-2007-5659
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and previous versions allow remote malicious users to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
Adobe Acrobat Reader
Adobe Acrobat
2 EDB exploits
2 Articles
9
CVSSv2
CVE-2014-7288
Symantec PGP Universal Server and Encryption Management Server prior to 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.
Symantec Encryption Management Server
Symantec Pgp Universal Server
1 EDB exploit
8.5
CVSSv2
CVE-2013-6226
Directory traversal vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) prior to 5.0.4 allows remote malicious users to read or delete arbitrary files via unspecified vectors.
Ajaxplorer Ajaxplorer 3.1.1
Ajaxplorer Ajaxplorer 2.5
Ajaxplorer Ajaxplorer 3.3.2
Ajaxplorer Ajaxplorer 3.0.1
Ajaxplorer Ajaxplorer 4.2.3
Ajaxplorer Ajaxplorer 4.0.4
Ajaxplorer Ajaxplorer 3.3.4
Ajaxplorer Ajaxplorer 5.0.1
Ajaxplorer Ajaxplorer 3.0
Ajaxplorer Ajaxplorer 2.7.2
Ajaxplorer Ajaxplorer 3.1
Ajaxplorer Ajaxplorer 3.2.3
Ajaxplorer Ajaxplorer 2.6.0
Ajaxplorer Ajaxplorer 2.5.4
Ajaxplorer Ajaxplorer 4.2.2
Ajaxplorer Ajaxplorer 2.3.3
Ajaxplorer Ajaxplorer 5.0.2
Ajaxplorer Ajaxplorer 3.2.1
Ajaxplorer Ajaxplorer 3.2.5
Ajaxplorer Ajaxplorer
Ajaxplorer Ajaxplorer 4.0.3
Ajaxplorer Ajaxplorer 2.3.4
8.5
CVSSv2
CVE-2013-6027
Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/runtime/diagnostic/pingIp parameter to Tools/tools_misc.xgi.
Dlink Dir-100 -
1 EDB exploit
8.5
CVSSv2
CVE-2009-3369
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another ...
Craig Barratt Backuppc 3.1.0
7.8
CVSSv2
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually writ...
Apple Swiftnio
Apache Traffic Server
Apache Http Server
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 19.04
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Synology Skynas -
Synology Diskstation Manager 6.2
Synology Vs960hd Firmware -
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Opensuse Leap 15.0
Opensuse Leap 15.1
Redhat Software Collections 1.0
Redhat Jboss Core Services 1.0
Redhat Enterprise Linux 8.0
Redhat Jboss Enterprise Application Platform 7.2.0
Redhat Quay 3.0.0
Redhat Openshift Service Mesh 1.0
Redhat Jboss Enterprise Application Platform 7.3.0
1 Github repository
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »