Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
include security research vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2012-5190
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
Accusoft Prizm Content Connect 5.1
1 EDB exploit
8.8
CVSSv3
CVE-2023-25356
CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can...
Coredial Sipxcom
1 Github repository
8.8
CVSSv3
CVE-2023-25355
CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the `daemon` user on a sipXcom server can overwrite a service file, and escalate their privileges to `root`.
Coredial Sipxcom
1 Github repository
8.6
CVSSv3
CVE-2024-24919
Potentially allowing an malicious user to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Checkpoint Quantum Security Gateway Firmware R80.40
Checkpoint Cloudguard Network Security R81.20
Checkpoint Cloudguard Network Security R81.10
Checkpoint Cloudguard Network Security R81.0
Checkpoint Cloudguard Network Security R80.40
Checkpoint Quantum Security Gateway Firmware R81.20
Checkpoint Quantum Security Gateway Firmware R81.10
Checkpoint Quantum Security Gateway Firmware R81.0
Checkpoint Quantum Spark Firmware R81.10
Checkpoint Quantum Spark Firmware R80.20
26 Github repositories
3 Articles
7.8
CVSSv3
CVE-2017-13091
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified padding in CBC mode allows use of an EDA tool as a decryption oracle. The methods a...
- - -
7.8
CVSSv3
CVE-2017-13092
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified HDL syntax allows use of an EDA tool as a decryption oracle. The methods are flawed...
- - -
7.8
CVSSv3
CVE-2017-13093
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of encrypted IP cyphertext to insert hardware trojans. The methods are flawed and, in the m...
- - -
7.8
CVSSv3
CVE-2017-13094
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of the encryption key and insertion of hardware trojans in any IP. The methods are flawed a...
- - -
7.8
CVSSv3
CVE-2017-13095
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of a license-deny response to a license grant. The methods are flawed and, in the most egre...
- - -
7.8
CVSSv3
CVE-2017-13096
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of Rights Block to remove or relax access control. The methods are flawed and, in the most ...
- - -
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »