Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
proxy vulnerabilities and exploits
(subscribe to this query)
5.8
CVSSv2
CVE-2020-11053
In OAuth2 Proxy prior to 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the original URL that the user was trying to access. This re...
Oauth2 Proxy Project Oauth2 Proxy
5
CVSSv2
CVE-2018-19784
The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for malicious users to calculate the authorization data needed for local file inclusion.
Php-proxy Php-proxy 5.1.0
7.5
CVSSv2
CVE-2021-41739
A OS Command Injection vulnerability exists in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
Artica-proxy Artica Proxy 4.30.000000
6.8
CVSSv2
CVE-2017-1000069
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
Oauth2 Proxy Project Oauth2 Proxy 2.1
6
CVSSv2
CVE-2008-0633
Buffer overflow in Anon Proxy Server 0.102 and previous versions, when user authentication is enabled, allows remote malicious users to cause a denial of service (exception) via a user name with a large number of quotes, which triggers the overflow during escaping.
Anon Proxy Server Anon Proxy Server
1 EDB exploit
10
CVSSv2
CVE-2008-4541
Heap-based buffer overflow in the FTP subsystem in Sun Java System Web Proxy Server 4.0 up to and including 4.0.7 allows remote malicious users to execute arbitrary code via a crafted HTTP GET request.
Sun Java System Web Proxy Server 4.0
Sun Java System Web Proxy Server 4.0.1
Sun Java System Web Proxy Server 4.0.3
Sun Java System Web Proxy Server 4.0.4
Sun Java System Web Proxy Server 4.0.6
Sun Java System Web Proxy Server 4.0.5
Sun Java System Web Proxy Server 4.0.7
Sun Java System Web Proxy Server 4.0.2
5
CVSSv2
CVE-2017-16037
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing malicious users to access any file in the system by placing '../' in the URL.
Gomeplus-h5-proxy Project Gomeplus-h5-proxy
5
CVSSv2
CVE-2002-2286
The parse-get function in utils.c for apt-www-proxy 0.1 allows remote malicious users to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference.
Apt-www-proxy Apt-www-proxy 0.1
7.5
CVSSv2
CVE-2021-21322
fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is `/pub/`, a user e...
Fastify-http-proxy Project Fastify-http-proxy
6.8
CVSSv2
CVE-2007-6459
Anon Proxy Server 0.100, and probably 0.101, allows remote malicious users to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a different vulnerability...
Anon Proxy Server Anon Proxy Server 0.100
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »