Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
manuel garcia cardenas vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2019-9618
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
Gracemedia Media Player Project Gracemedia Media Player 1.0
1 EDB exploit
7.5
CVSSv2
CVE-2018-10969
SQL injection vulnerability in the Pie Register plugin prior to 3.0.10 for WordPress allows remote malicious users to execute arbitrary SQL commands via the invitation codes grid.
Genetechsolutions Pie Register
1 EDB exploit
7.5
CVSSv2
CVE-2018-7474
An issue exists in Textpattern CMS 4.6.2 and previous versions. It is possible to inject SQL code in the variable "qty" on the page index.php.
Textpattern Textpattern
1 EDB exploit
7.5
CVSSv2
CVE-2017-14125
SQL injection vulnerability in the Responsive Image Gallery plugin prior to 1.2.1 for WordPress allows remote malicious users to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
Wpdevart Responsive Image Gallery Gallery Album
7.5
CVSSv2
CVE-2016-7400
Multiple SQL injection vulnerabilities in Exponent CMS prior to 2.4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id ...
Exponentcms Exponent Cms
1 EDB exploit
5.8
CVSSv2
CVE-2013-2621
Open Redirection Vulnerability in the redir.php script in Telaen prior to 1.3.1 allows remote malicious users to redirect victims to arbitrary websites via a crafted URL.
Telaen Project Telaen
1 EDB exploit
5.8
CVSSv2
CVE-2019-12922
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
Phpmyadmin Phpmyadmin
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Fedoraproject Fedora 31
1 EDB exploit
5.5
CVSSv2
CVE-2013-3831
Unspecified vulnerability in the Oracle Portal component in Oracle Fusion Middleware 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Demos.
Oracle Fusion Middleware 11.1.1.6.0
5
CVSSv2
CVE-2013-2624
Telean prior to 1.3.1 contains a full path disclosure vulnerability which could allow remote malicious users to obtain sensitive information through a specially crafted URL request.
Telaen Project Telaen
1 EDB exploit
5
CVSSv2
CVE-2013-2631
TinyWebGallery (TWG) 1.8.9 and previous versions contains a full path disclosure vulnerability which allows remote malicious users to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
Tinywebgallery Tinywebgallery
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27802
template injection
CVE-2024-0044
code injection
CVE-2024-35474
CVE-2024-27857
CVE-2024-23251
CVE-2024-23692
physical
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »