Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
felipe molina vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2013-7204
Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote malicious users to hijack the authentication of administrators for requests that add arbitrary users.
Conceptronic Cipcamptiwl 1.0 Firmware 21.37.2.49
Conceptronic Cipcamptiwl 1.0
1 EDB exploit
10
CVSSv2
CVE-2020-11698
An issue exists in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote malicious user to inject commands into the file snmpd.conf that would allow executing commands on the target server.
Titanhq Spamtitan 7.07
9
CVSSv2
CVE-2020-11699
An issue exists in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an malicious user to execute remote code on the target server. The user has to be authenticated before interacting with this page.
Titanhq Spamtitan 7.07
4
CVSSv2
CVE-2020-11700
An issue exists in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an malicious user to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.
Titanhq Spamtitan 7.07
6.5
CVSSv2
CVE-2020-11803
An issue exists in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be au...
Titanhq Spamtitan 7.07
6.5
CVSSv2
CVE-2020-11804
An issue exists in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.
Titanhq Spamtitan 7.07
4.3
CVSSv2
CVE-2019-15083
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 prior to 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine Servic...
Zohocorp Manageengine Servicedesk Plus 10.0.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started