Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
inject vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2014-0029
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters.
Redhat Subscription Asset Manager 1.0.0
383
VMScore
CVE-2015-0881
CRLF injection vulnerability in Squid prior to 3.1.1 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
Squid-cache Squid
NA
CVE-2022-47877
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.
Jedox Jedox 2020.2.5
312
VMScore
CVE-2017-11691
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote malicious users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
Cacti Cacti 1.1.13
605
VMScore
CVE-2007-1926
Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin prior to 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (...
Jbmc Software Directadmin
445
VMScore
CVE-2015-7318
Plone 3.3.0 up to and including 3.3.6 allows remote malicious users to inject headers into HTTP responses.
Plone Plone 3.3.1
Plone Plone 3.3.3
Plone Plone 3.3.4
Plone Plone 3.3.5
Plone Plone 3.3.6
Plone Plone 3.3
Plone Plone 3.3.2
294
VMScore
CVE-2018-10932
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an malicious user to inject shell control characters into the buffer and impact the behavior of the terminal.
Intel Lldptool
454
VMScore
CVE-2010-0092
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, and 5.0 Update 23 allows remote malicious users to affect confidentiality, integrity, and availability via unknown vectors.
Sun Jre
Sun Jre 1.6.0
Sun Jdk 1.6.0
Sun Jdk
Sun Jdk 1.5.0
Sun Jre 1.5.0
454
VMScore
CVE-2010-0082
Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote malicious users to affect confidentiality, integrity, and availability via unknown vectors.
Sun Jre
Sun Jre 1.6.0
Sun Jdk 1.6.0
Sun Jdk
Sun Jdk 1.5.0
Sun Sdk 1.4.2 12
Sun Sdk 1.4.2 13
Sun Sdk 1.4.2 3
Sun Sdk 1.4.2 4
Sun Sdk 1.4.2 21
Sun Sdk 1.4.2 22
Sun Sdk 1.4.2 23
Sun Sdk 1.4.2 02
Sun Sdk 1.4.2 1
Sun Sdk 1.4.2 16
Sun Sdk 1.4.2 17
Sun Sdk 1.4.2 7
Sun Sdk 1.4.2 8
Sun Sdk 1.4.2
Sun Sdk 1.4.2 14
Sun Sdk 1.4.2 15
Sun Sdk 1.4.2 5
445
VMScore
CVE-2010-0084
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote malicious users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-0091.
Sun Jre 1.6.0
Sun Jre
Sun Jdk 1.6.0
Sun Jdk
Sun Jdk 1.5.0
Sun Sdk 1.4.2 10
Sun Sdk 1.4.2 11
Sun Sdk 1.4.2 18
Sun Sdk 1.4.2 19
Sun Sdk 1.4.2 9
Sun Sdk 1.4.2 20
Sun Sdk 1.4.2
Sun Sdk 1.4.2 14
Sun Sdk 1.4.2 15
Sun Sdk 1.4.2 5
Sun Sdk 1.4.2 6
Sun Sdk 1.4.2 24
Sun Sdk
Sun Sdk 1.4.2 12
Sun Sdk 1.4.2 13
Sun Sdk 1.4.2 3
Sun Sdk 1.4.2 4
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48654
CVE-2024-2757
authentication bypass
CVE-2024-3194
CVE-2024-33640
CVE-2024-21111
dos
insecure direct object reference
CVE-2024-21345
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »