Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
unauthorized vulnerabilities and exploits
(subscribe to this query)
755
VMScore
CVE-2005-0316
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote malicious users to bypass intended access restrictions.
Webwasher Webwasher Classic 2.2.1
Webwasher Webwasher Classic 3.3
1 EDB exploit
578
VMScore
CVE-2018-19359
GitLab Community and Enterprise Edition 8.9 and later and prior to 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.
Gitlab Gitlab 11.5.0
Gitlab Gitlab
356
VMScore
CVE-2015-4225
Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.
Cisco Nx-os 1.0\\(1.110a\\)
Cisco Nx-os 1.0\\(1e\\)
1000
VMScore
CVE-2002-2425
Sun AnswerBook2 1.2 up to and including 1.4.2 allows remote malicious users to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.
Sun Solaris Answerbook2 1.2
Sun Solaris Answerbook2 1.4
Sun Solaris Answerbook2 1.4.1
Sun Solaris Answerbook2 1.4.2
Sun Solaris Answerbook2 1.3
1 EDB exploit
605
VMScore
CVE-2016-6377
Media Origination System Suite Software 2.6 and previous versions in Cisco Virtual Media Packager (VMP) allows remote malicious users to bypass authentication and make arbitrary Platform and Applications Manager (PAM) API calls via unspecified vectors, aka Bug ID CSCuz52110.
Cisco Media Origination System Suite 2.3 Base
Cisco Media Origination System Suite 2.3\\(7\\)
Cisco Media Origination System Suite 2.3\\(8\\)
Cisco Media Origination System Suite 2.4\\(1\\)
Cisco Media Origination System Suite 2.3\\(2\\)
Cisco Media Origination System Suite 2.3\\(6\\)
Cisco Media Origination System Suite 2.6 Base
Cisco Media Origination System Suite 2.3\\(1\\)
Cisco Media Origination System Suite 2.4 Base
Cisco Media Origination System Suite 2.5 Base
Cisco Media Origination System Suite 2.5\\(0\\)
Cisco Media Origination System Suite 2.5\\(1\\)
755
VMScore
CVE-2005-2729
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote malicious users to bypass firewall rules and connect to local services.
Astaro Security Linux 6.001
1 EDB exploit
505
VMScore
CVE-2000-0705
ntop running in web mode allows remote malicious users to read arbitrary files via a .. (dot dot) attack.
Luca Deri Ntop 1.2a7 9
1 EDB exploit
755
VMScore
CVE-2001-1188
mailto.exe in Brian Dorricott MAILTO 1.0.9 and previous versions allows remote malicious users to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fields.
Brian Dorricott Mailto 1.0.7
Brian Dorricott Mailto 1.0.8
Brian Dorricott Mailto 1.0.9
1 EDB exploit
1000
VMScore
CVE-2003-1160
FlexWATCH Network video server 132 allows remote malicious users to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).
Seyeon Flexwatch Network Video Server 2.2
Seyeon Flexwatch Network Video Server Model 132
1 EDB exploit
NA
CVE-2023-20230
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote malicious user to read, modify, or delete non-tenant policies (for example, access policies) created by users associa...
Cisco Application Policy Infrastructure Controller
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »