Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
st vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-4681
Cross-site scripting (XSS) vulnerability in search.php in phpDirectorySource 1.x allows remote malicious users to inject arbitrary web script or HTML via the st parameter.
Phpdirectorysource Phpdirectorysource 1.1
Phpdirectorysource Phpdirectorysource 1.0
1 EDB exploit
NA
CVE-2007-2916
Cross-site scripting (XSS) vulnerability in showown.php in GMTT Music Distro 1.2 allows remote malicious users to inject arbitrary web script or HTML via the st parameter.
Gmtt Music Distro 1.2
NA
CVE-2004-1406
SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 up to and including 3.1.3 allows remote malicious users to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.
Ikonboard.com Ikonboard 3.0.1
Ikonboard.com Ikonboard 3.1.3
Ikonboard.com Ikonboard 3.1.1
Ikonboard.com Ikonboard 3.1.2a
1 EDB exploit
9.8
CVSSv3
CVE-2023-33625
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 exists to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
Dlink Dir-600 Firmware 2.18
5.4
CVSSv3
CVE-2020-15037
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an malicious user to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.
Nedi Nedi 1.9c
NA
CVE-2007-6281
Heap-based buffer overflow in Open File Manager service (ofmnt.exe) in St. Bernard Open File Manager 9.5 allows remote malicious users to execute arbitrary code via a long request.
Stbernard Open File Manager 9.5
NA
CVE-2006-1076
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote malicious users to execute arbitrary SQL commands via the st parameter.
Invision Power Services Invision Power Board 2.1.5
1 EDB exploit
NA
CVE-2008-2458
Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the st parameter.
4shared Starsgames Control Panel
1 EDB exploit
7.5
CVSSv3
CVE-2014-3744
Directory traversal vulnerability in the st module prior to 0.2.5 for Node.js allows remote malicious users to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.
Nodejs Node.js
4.7
CVSSv3
CVE-2023-1990
A use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an malicious user to crash the system due to a race problem.
Linux Linux Kernel
Linux Linux Kernel 6.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »