Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pietro oliva vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2020-17360
An issue exists in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multiple boundary checks that are performed to prevent out-of-bounds memory read/write. However, two of these boundary checks contain an integer overflow that leads to a bypa...
Readytalk Avian 1.2.0
5.5
CVSSv3
CVE-2020-17361
An issue exists in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h returns silently when a negative length is provided (instead of throwing an exception). This could result in data being lost during the copy, with varying consequences depending on th...
Readytalk Avian 1.2.0
6.5
CVSSv3
CVE-2014-1889
The Group creation process in the Buddypress plugin prior to 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
Buddypress Buddypress
1 EDB exploit
8.8
CVSSv3
CVE-2020-13224
TP-LINK NC200 devices up to and including 2.1.10 build 200401, NC210 devices up to and including 1.0.10 build 200401, NC220 devices up to and including 1.3.1 build 200401, NC230 devices up to and including 1.3.1 build 200401, NC250 devices up to and including 1.3.1 build 200401, ...
Tp-link Nc200 Firmware
Tp-link Nc210 Firmware
Tp-link Nc220 Firmware
Tp-link Nc230 Firmware
Tp-link Nc250 Firmware
Tp-link Nc260 Firmware
Tp-link Nc450 Firmware
9.8
CVSSv3
CVE-2020-25023
An issue exists in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access.
Noise-java Project Noise-java
9.8
CVSSv3
CVE-2020-25021
An issue exists in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds access.
Noise-java Project Noise-java
NA
CVE-2014-7958
Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the dbhost parameter.
Ait-pro Bulletproof Security .50.4
Ait-pro Bulletproof Security .50.3
Ait-pro Bulletproof Security .44.1
Ait-pro Bulletproof Security .44
Ait-pro Bulletproof Security .49.3
Ait-pro Bulletproof Security .49.2
Ait-pro Bulletproof Security .48.5
Ait-pro Bulletproof Security .48.4
Ait-pro Bulletproof Security .47.7
Ait-pro Bulletproof Security .47.6
Ait-pro Bulletproof Security .47.5
Ait-pro Bulletproof Security .46.8
Ait-pro Bulletproof Security .46.7
Ait-pro Bulletproof Security .46
Ait-pro Bulletproof Security .45.9
Ait-pro Bulletproof Security .50.6
Ait-pro Bulletproof Security .50.5
Ait-pro Bulletproof Security .45.1
Ait-pro Bulletproof Security .45
Ait-pro Bulletproof Security .49.5
Ait-pro Bulletproof Security .49.4
Ait-pro Bulletproof Security .48.7
NA
CVE-2014-7959
SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tableprefix parameter.
Ait-pro Bulletproof Security .45.4
Ait-pro Bulletproof Security .45.5
Ait-pro Bulletproof Security .45.6
Ait-pro Bulletproof Security .46.3
Ait-pro Bulletproof Security .46.4
Ait-pro Bulletproof Security .47.1
Ait-pro Bulletproof Security .47.2
Ait-pro Bulletproof Security .48
Ait-pro Bulletproof Security .48.1
Ait-pro Bulletproof Security .48.8
Ait-pro Bulletproof Security .48.9
Ait-pro Bulletproof Security .49.6
Ait-pro Bulletproof Security .49.7
Ait-pro Bulletproof Security .45.2
Ait-pro Bulletproof Security .45.3
Ait-pro Bulletproof Security .50.7
Ait-pro Bulletproof Security .50.8
Ait-pro Bulletproof Security .45.9
Ait-pro Bulletproof Security .46
Ait-pro Bulletproof Security .46.7
Ait-pro Bulletproof Security .46.8
Ait-pro Bulletproof Security .47.5
9.8
CVSSv3
CVE-2020-25022
An issue exists in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.
Noise-java Project Noise-java
NA
CVE-2014-1888
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin prior to 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by le...
Buddypress Buddypress
Buddypress Buddypress 1.8.1
Buddypress Buddypress 1.6.3
Buddypress Buddypress 1.6.2
Buddypress Buddypress 1.5.5
Buddypress Buddypress 1.5.6
Buddypress Buddypress 1.7
Buddypress Buddypress 1.6.5
Buddypress Buddypress 1.6.4
Buddypress Buddypress 1.5.3.1
Buddypress Buddypress 1.5.4
Buddypress Buddypress 1.7.2
Buddypress Buddypress 1.7.1
Buddypress Buddypress 1.5.2
Buddypress Buddypress 1.5.3
Buddypress Buddypress 1.6.1
Buddypress Buddypress 1.8
Buddypress Buddypress 1.7.3
Buddypress Buddypress 1.5
Buddypress Buddypress 1.5.1
Buddypress Buddypress 1.5.7
Buddypress Buddypress 1.6
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »