Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vam vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2011-0503
Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote malicious users to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php or (2) change user permissions via a...
Vamsoft Vam Shop
Vamsoft Vam Shop 1.6
1 EDB exploit
4.3
CVSSv2
CVE-2011-0504
Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote malicious users to inject arbitrary web script or HTML via the (1) status parameter to admin/orders.php, (2) search parameter to admin/customers.php, or (3) STORE...
Vamshop Vam Shop 1.6
Vamshop Vam Shop 1.6.1
1 EDB exploit
7.3
CVSSv3
CVE-2025-2353
A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file /vam/index.php of the component HTTP GET Parameter Handler. The manipulation of the argument ID/registry_id/plane_icao leads to sq...
Vam Virtual Airlines Manager
5.4
CVSSv3
CVE-2019-19991
An issue exists in Selesta Visual Access Manager (VAM) 4.15.0 up to and including 4.29. Multiple Reflected Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /vam/vam_anagraphic.php, /vam/vam_vamuse...
Seling Visual Access Manager
5.4
CVSSv3
CVE-2019-19990
An issue exists in Selesta Visual Access Manager (VAM) 4.15.0 up to and including 4.29. Multiple Stored Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /monitor/s_headmodel.php and /vam/vam_user....
Seling Visual Access Manager
NA
CVE-2023-42238
An issue exists in Selesta Visual Access Manager (VAM) before 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.
NA
CVE-2023-42237
An issue exists in Selesta Visual Access Manager (VAM) before 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
8.8
CVSSv3
CVE-2023-42244
An issue exists in Selesta Visual Access Manager (VAM) before 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.
NA
CVE-2023-42239
An issue exists in Selesta Visual Access Manager (VAM) before 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php.
NA
CVE-2023-42241
An issue exists in Selesta Visual Access Manager (VAM) before 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_anagraphic.php.
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2025-46656
unknown
CVE-2025-46577
CVE-2025-32979
paicoding
XPath injection
hackmd
CVE-2025-3643
opplus
CSRF
local users
CVE-2025-32433
CVE-2025-32432
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »