Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kacper szurek vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2014-9013
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
Wpmarketplace Project Wpmarketplace 2.4.0
2 EDB exploits
4.3
CVSSv3
CVE-2014-9014
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin prior to 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.
Wpmarketplace Project Wpmarketplace 2.4.0
2 EDB exploits
8.8
CVSSv3
CVE-2014-9312
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
10web Photo Gallery 1.2.5
1 EDB exploit
9.8
CVSSv3
CVE-2017-11153
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to gain administrator privileges via a crafted serialized payload.
Synology Photo Station 6.3-2967
Synology Photo Station
1 EDB exploit
7.2
CVSSv3
CVE-2017-11154
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to create arbitrary PHP scripts via the type parameter.
Synology Photo Station
Synology Photo Station 6.3-2967
1 EDB exploit
7.5
CVSSv3
CVE-2017-11155
An information exposure vulnerability in index.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to obtain sensitive system information via unspecified vectors.
Synology Photo Station 6.3-2967
Synology Photo Station
1 EDB exploit
9.8
CVSSv3
CVE-2017-11151
A vulnerability in synotheme_upload.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to upload arbitrary files without authentication via the logo_upload action.
Synology Photo Station
Synology Photo Station 6.3-2967
1 EDB exploit
7.5
CVSSv3
CVE-2017-11152
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station prior to 6.7.3-3432 and 6.3-2967 allows remote malicious users to write arbitrary files via the path parameter.
Synology Photo Station 6.3-2967
Synology Photo Station
1 EDB exploit
8.2
CVSSv3
CVE-2014-9262
The Duplicator plugin in Wordpress prior to 0.5.10 allows remote authenticated users to create and download backup files.
Snapcreek Duplicator
1 EDB exploit
8.8
CVSSv3
CVE-2014-9260
The basic_settings function in the download manager plugin for WordPress prior to 2.7.3 allows remote authenticated users to update every WordPress option.
Downloadmanager Download Manager
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-3611
CVE-2024-4947
CVE-2024-32988
CVE-2020-35165
local file inclusion
CVE-2024-4980
bypass
malicious code
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »