Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
validation vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2018-17215
An information-disclosure issue exists in Postman up to and including 6.3.0. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortunately, the associated HTTPS request data is sent anyway. Only the response is not displayed. ...
Postman Postman
NA
CVE-2005-0494
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.
Thomson Thomson Cable Modem Tcw690
1 EDB exploit
NA
CVE-2004-0846
Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote malicious users to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
Microsoft Excel X
Microsoft Office 2000
Microsoft Excel 2001
Microsoft Excel 2002
Microsoft Office 2001
Microsoft Office V.x
Microsoft Excel 2000
NA
CVE-2006-1916
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) ulocation or (2) uhobbies parameters.
Dbbs Dbbs 2.0
Dbbs Dbbs
1 EDB exploit
5.7
CVSSv3
CVE-2018-3815
The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated malicious user to ...
Stalker Communigate Pro 6.2
NA
CVE-2002-1673
The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by inserting the script into certain files or fields, such as a real user name entry...
Webmin Webmin 0.1
Webmin Webmin 0.41
Webmin Webmin 0.42
Webmin Webmin 0.78
Webmin Webmin 0.79
Webmin Webmin 0.80
Webmin Webmin 0.92.1
Webmin Webmin 0.22
Webmin Webmin 0.3
Webmin Webmin 0.6
Webmin Webmin 0.7
Webmin Webmin 0.85
Webmin Webmin 0.88
Webmin Webmin 0.31
Webmin Webmin 0.4
Webmin Webmin 0.76
Webmin Webmin 0.77
Webmin Webmin 0.91
Webmin Webmin 0.92
Webmin Webmin 0.2
Webmin Webmin 0.21
Webmin Webmin 0.5
1 EDB exploit
7.4
CVSSv3
CVE-2021-1134
A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote malicious user to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 ...
Cisco Dna Center
NA
CVE-2006-5943
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote malicious users to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.
Website Designs For Less Inventory Manager
1 EDB exploit
NA
CVE-2009-0050
Lasso 2.2.1 and previous versions does not properly check the return value from the OpenSSL DSA_verify function, which allows remote malicious users to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Entrouvert Lasso
Entrouvert Lasso 2.0.0-1
Entrouvert Lasso 1.9.9.0
NA
CVE-2004-1537
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 up to and including 1.6.1 allows remote malicious users to execute arbitrary web script via the img parameter.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.03
Phpkit Phpkit 1.6.1
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
CVE-2006-4304
CVE-2023-26603
CVE-2024-28327
CVE-2023-50363
CVE-2024-21905
template injection
CVE-2024-3400
cross-site request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »