Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
manuel garcia cardenas vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2017-14125
SQL injection vulnerability in the Responsive Image Gallery plugin prior to 1.2.1 for WordPress allows remote malicious users to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
Wpdevart Responsive Image Gallery Gallery Album
5.4
CVSSv3
CVE-2019-11226
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
Cmsmadesimple Cms Made Simple 2.2.10
5.4
CVSSv3
CVE-2020-8789
Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.
Composr Project Composr
NA
CVE-2013-2652
CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and previous versions allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.
Andrew Simpson Webcollab 3.21
Andrew Simpson Webcollab 3.20
Andrew Simpson Webcollab
Andrew Simpson Webcollab 2.60
Andrew Simpson Webcollab 2.50
Andrew Simpson Webcollab 2.01
Andrew Simpson Webcollab 2.00
Andrew Simpson Webcollab 1.62
Andrew Simpson Webcollab 1.61
Andrew Simpson Webcollab 1.32
Andrew Simpson Webcollab 1.31
Andrew Simpson Webcollab 3.10
Andrew Simpson Webcollab 3.00
Andrew Simpson Webcollab 2.30
Andrew Simpson Webcollab 2.20
Andrew Simpson Webcollab 1.71a
Andrew Simpson Webcollab 1.71
Andrew Simpson Webcollab 1.51
Andrew Simpson Webcollab 1.50
Andrew Simpson Webcollab 1.42
Andrew Simpson Webcollab 2.40
Andrew Simpson Webcollab 2.31
6.1
CVSSv3
CVE-2013-2622
Cross-site Scripting (XSS) in UebiMiau 2.7.11 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the "selected_theme" parameter in error.php.
Uebimiau Uebimiau
5.3
CVSSv3
CVE-2013-2631
TinyWebGallery (TWG) 1.8.9 and previous versions contains a full path disclosure vulnerability which allows remote malicious users to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
Tinywebgallery Tinywebgallery
NA
CVE-2013-2651
Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php.
Boltwire Boltwire 3.06
Boltwire Boltwire 3.07
Boltwire Boltwire 3.14
Boltwire Boltwire 3.15
Boltwire Boltwire 3.2.3
Boltwire Boltwire 3.2.4
Boltwire Boltwire 3.3
Boltwire Boltwire 3.3.1
Boltwire Boltwire 3.3.8
Boltwire Boltwire 3.3.9
Boltwire Boltwire 3.4.6
Boltwire Boltwire 3.4.7
Boltwire Boltwire 3.4.8
Boltwire Boltwire 3.4.15
Boltwire Boltwire 3.4.16
Boltwire Boltwire 3.04
Boltwire Boltwire 3.05
Boltwire Boltwire 3.12
Boltwire Boltwire 3.13
Boltwire Boltwire 3.2.1
Boltwire Boltwire 3.2.2
Boltwire Boltwire 3.2.10
NA
CVE-2013-3831
Unspecified vulnerability in the Oracle Portal component in Oracle Fusion Middleware 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Demos.
Oracle Fusion Middleware 11.1.1.6.0
6.1
CVSSv3
CVE-2013-2623
Cross-site Scripting (XSS) in Telaen prior to 1.3.1 allows remote malicious users to inject arbitrary web script or HTML via the "f_email" parameter in index.php.
Telaen Project Telaen
1 EDB exploit
6.1
CVSSv3
CVE-2013-2621
Open Redirection Vulnerability in the redir.php script in Telaen prior to 1.3.1 allows remote malicious users to redirect victims to arbitrary websites via a crafted URL.
Telaen Project Telaen
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »