Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
trustwave.com vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2012-5192
Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and previous versions allows remote malicious users to read arbitrary files via "''%2F" (dot dot encoded slash) sequences in the overlay_type parameter.
Bitweaver Bitweaver 2.7
Bitweaver Bitweaver 2.6
Bitweaver Bitweaver 2.5
Bitweaver Bitweaver 2.0.2
Bitweaver Bitweaver 1.1
Bitweaver Bitweaver
Bitweaver Bitweaver 2.0.0
Bitweaver Bitweaver 1.3
Bitweaver Bitweaver 1.1.1 Beta
Bitweaver Bitweaver 1.3.1
Bitweaver Bitweaver 1.2.1
1 EDB exploit
NA
CVE-2013-7247
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions prior to 2.4.0 allows remote malicious users to discover sensitive information (user names and password hashes) via the cmdWebGetConfiguration action in a TSA_REQUEST.
Franklinfueling Ts-550 Evo Firmware 2.0.0.6833
Franklinfueling Ts-550 Evo Firmware 2.3.1.7492
Franklinfueling Ts-550 Evo -
1 EDB exploit
NA
CVE-2013-7248
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions prior to 2.4.0 has a hardcoded password for the roleDiag account, which allows remote malicious users to gain root privileges, as demonstrated using a cmdWebCheckRole action in a TSA_REQUEST.
Franklinfueling Ts-550 Evo Firmware 2.3.1.7492
Franklinfueling Ts-550 Evo Firmware 2.0.0.6833
Franklinfueling Ts-550 Evo -
1 EDB exploit
NA
CVE-2013-4884
Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote malicious users to inject arbitrary web script or HTML via UTF-7 encoded sequences in a server response, which is not properly handled in the SuperScan HTML report.
Mcafee Superscan 4.0
1 EDB exploit
NA
CVE-2013-5688
Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and previous versions allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3...
Ajaxplorer Ajaxplorer 4.0.4
Ajaxplorer Ajaxplorer 3.2
Ajaxplorer Ajaxplorer 3.1.1
Ajaxplorer Ajaxplorer 3.1
Ajaxplorer Ajaxplorer 3.0.3
Ajaxplorer Ajaxplorer 5.0.1
Ajaxplorer Ajaxplorer 5.0.0
Ajaxplorer Ajaxplorer 4.2.3
Ajaxplorer Ajaxplorer 4.2.2
Ajaxplorer Ajaxplorer 3.3.4
Ajaxplorer Ajaxplorer 3.3.3
Ajaxplorer Ajaxplorer 3.3.2
Ajaxplorer Ajaxplorer 3.2.5
Ajaxplorer Ajaxplorer 2.7.2
Ajaxplorer Ajaxplorer 2.7.1
Ajaxplorer Ajaxplorer 2.6.0
Ajaxplorer Ajaxplorer 2.5.5
Ajaxplorer Ajaxplorer 4.0.3
Ajaxplorer Ajaxplorer 4.0.1
Ajaxplorer Ajaxplorer 3.3.5
Ajaxplorer Ajaxplorer 3.2.4
Ajaxplorer Ajaxplorer 3.2.2
1 EDB exploit
NA
CVE-2013-5689
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5688. Reason: This issue has been MERGED with CVE-2013-5688 in accordance with CVE content decisions, because it is the same type of vulnerability affecting the same versions. Notes: All CVE users should refe...
1 EDB exploit
NA
CVE-2013-5745
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and previous versions, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remo...
David King Vino 3.6.2
David King Vino
David King Vino 3.4.2
David King Vino 3.2.1
David King Vino 3.2.0
David King Vino 3.1.2
David King Vino 3.1.1
David King Vino 2.99.3
David King Vino 2.99.2
David King Vino 2.8.0
David King Vino 3.6.0
David King Vino 3.6.1
David King Vino 3.3.1
David King Vino 3.2.2
David King Vino 3.1.4
David King Vino 3.1.3
David King Vino 3.0.0
David King Vino 2.99.5
David King Vino 2.99.4
David King Vino 2.8.1
David King Vino 2.8.0.1
David King Vino 2.7.4.90
1 EDB exploit
NA
CVE-2013-4620
Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote malicious users to inject arbitrary web script or HTML via the note parameter.
Open-emr Openemr 4.1.1
1 EDB exploit
NA
CVE-2013-4619
Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php, or the (3) form_newid parameter to custom/chart_tracker.php.
Open-emr Openemr 4.1.1
NA
CVE-2013-1194
The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggressive-mode messages depending on whether invalid VPN groups are specified, which allows remote malicious users to enumerate groups via a series of messages, ak...
Cisco Adaptive Security Appliance Software -
Cisco Adaptive Security Appliance
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »