Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
framework vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2009-4417
The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent malicious users to send arbitrary e-mail messages to any recipient address via vectors related to "events not yet mailed."
Zend Framework
Zend Framework 0.1.3
Zend Framework 0.1.4
Zend Framework 0.1.5
Zend Framework 0.2.0
Zend Framework 0.6.0
Zend Framework 0.7.0
Zend Framework 0.8.0
Zend Framework 0.9.0
Zend Framework 0.9.1
Zend Framework 0.9.2
Zend Framework 0.9.3
4.9
CVSSv2
CVE-2007-0516
Yana Framework prior to 2.8.5a allows remote authenticated users with permissions to modify a guestbook profile to modify or delete arbitrary guestbook profiles via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from thir...
Yana Framework Yana Framework
Yana Framework Yana Framework 2.8
Yana Framework Yana Framework 2.8.1
Yana Framework Yana Framework 2.8.2a
Yana Framework Yana Framework 2.8.3a
6.8
CVSSv2
CVE-2015-5161
The Zend_Xml_Security::scan in ZendXml prior to 1.0.1 and Zend Framework prior to 1.12.14, 2.x prior to 2.4.6, and 2.5.x prior to 2.5.2, when running under PHP-FPM in a threaded environment, allows remote malicious users to bypass security checks and conduct XML external entity (...
Zend Zend Framework 1.0.0
Zend Zend Framework 1.0.1
Zend Zend Framework 1.0.2
Zend Zend Framework 1.0.3
Zend Zend Framework 1.0.4
Zend Zend Framework 1.5.0
Zend Zend Framework 1.5.1
Zend Zend Framework 1.5.2
Zend Zend Framework 1.5.3
Zend Zend Framework 1.6.0
Zend Zend Framework 1.6.1
Zend Zend Framework 1.6.2
2 EDB exploits
7.5
CVSSv2
CVE-2014-2685
The GenericConsumer class in the Consumer component in ZendOpenId prior to 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 prior to 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote malicious users to bypas...
Zend Zend Framework
Zend Zend Framework 1.0.0
Zend Zend Framework 1.0.1
Zend Zend Framework 1.0.2
Zend Zend Framework 1.0.3
Zend Zend Framework 1.0.4
Zend Zend Framework 1.5.0
Zend Zend Framework 1.5.1
Zend Zend Framework 1.5.2
Zend Zend Framework 1.5.3
Zend Zend Framework 1.6.0
Zend Zend Framework 1.6.1
6.4
CVSSv2
CVE-2012-6531
(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x prior to 1.11.13 and 1.12.x prior to 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote malicious users to read arbitrary files or create TCP connections via an external entity reference ...
Zend Zend Framework 1.0.4
Zend Zend Framework 1.5.0
Zend Zend Framework 1.5.1
Zend Zend Framework 1.5.2
Zend Zend Framework 1.5.3
Zend Zend Framework 1.6.0
Zend Zend Framework 1.6.1
Zend Zend Framework 1.6.2
Zend Zend Framework 1.7.0
Zend Zend Framework 1.7.1
Zend Zend Framework 1.7.2
Zend Zend Framework 1.7.3
5
CVSSv2
CVE-2012-6532
(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x prior to 1.11.13 and 1.12.x prior to 1.12.0 allow remote malicious users to cause a denial of service (CPU consumption) via recursive or circular references in an XML entity definition in an XML...
Zend Zend Framework 1.0.4
Zend Zend Framework 1.5.0
Zend Zend Framework 1.5.1
Zend Zend Framework 1.5.2
Zend Zend Framework 1.5.3
Zend Zend Framework 1.6.0
Zend Zend Framework 1.6.1
Zend Zend Framework 1.6.2
Zend Zend Framework 1.7.0
Zend Zend Framework 1.7.1
Zend Zend Framework 1.7.2
Zend Zend Framework 1.7.3
7.5
CVSSv3
CVE-2016-9878
An issue exists in Pivotal Spring Framework prior to 3.2.18, 4.2.x prior to 4.2.9, and 4.3.x prior to 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
Pivotal Software Spring Framework
Pivotal Software Spring Framework 4.2.0
Pivotal Software Spring Framework 4.3.0
Vmware Spring Framework 3.2.1
Vmware Spring Framework 3.2.2
Vmware Spring Framework 3.2.3
Vmware Spring Framework 3.2.4
Vmware Spring Framework 3.2.5
Vmware Spring Framework 3.2.6
Vmware Spring Framework 3.2.7
Vmware Spring Framework 3.2.8
Vmware Spring Framework 3.2.9
9.6
CVSSv3
CVE-2015-5211
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in th...
Vmware Spring Framework 3.2.0
Vmware Spring Framework 3.2.1
Vmware Spring Framework 3.2.2
Vmware Spring Framework 3.2.3
Vmware Spring Framework 3.2.4
Vmware Spring Framework 3.2.5
Vmware Spring Framework 3.2.6
Vmware Spring Framework 3.2.7
Vmware Spring Framework 3.2.8
Vmware Spring Framework 3.2.9
Vmware Spring Framework 3.2.10
Vmware Spring Framework 3.2.11
2 Github repositories
6.8
CVSSv2
CVE-2013-7315
The Spring MVC in Spring Framework prior to 3.2.4 and 4.0.0.M1 up to and including 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent malicious users to read arbitrary files, cause a denial of service, and conduct CSR...
Springsource Spring Framework 3.0.0
Springsource Spring Framework 3.0.0.m1
Springsource Spring Framework 3.0.0.m2
Springsource Spring Framework 3.0.1
Springsource Spring Framework 3.0.2
Springsource Spring Framework 3.0.3
Springsource Spring Framework 3.0.4
Springsource Spring Framework 3.0.5
Vmware Spring Framework
Vmware Spring Framework 3.0.6
Vmware Spring Framework 3.0.7
Vmware Spring Framework 3.1.0
5
CVSSv2
CVE-2014-8088
The (1) Zend_Ldap class in Zend prior to 1.12.9 and (2) Zend\Ldap component in Zend 2.x prior to 2.2.8 and 2.3.x prior to 2.3.3 allows remote malicious users to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.
Zend Zend Framework
Zend Zend Framework 1.12.0
Zend Zend Framework 1.12.1
Zend Zend Framework 1.12.2
Zend Zend Framework 1.12.3
Zend Zend Framework 1.12.5
Zend Zend Framework 2.0.0
Zend Zend Framework 2.01
Zend Zend Framework 2.2.2
Zend Zend Framework 2.2.3
Zend Zend Framework 2.2.4
Zend Zend Framework 2.2.5
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
path traversal
CVE-2025-2657
CVE-2025-30066
CVE-2025-24813
apache commons vfs
CVE-2025-2478
validation
CVE-2025-2674
code injection
medical card generation system
microsoft edge (chromium-based)
CVE-2025-2688
cicadascms
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »