Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
unauthorized vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2017-6624
A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote malicious user to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections component of the affect...
Cisco Ios 15.5(3)m
NA
CVE-2003-1169
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.
Datev Nutzungskontrolle 2.2
Datev Nutzungskontrolle 2.1
1 EDB exploit
NA
CVE-2006-2280
Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and previous versions allows remote malicious users to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template parameter.
Openengine Openengine 1.8 Beta2
Openengine Openengine 1.7.1
1 EDB exploit
7.5
CVSSv3
CVE-2017-15235
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote malicious users to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.
Horde Groupware 5.2.21
1 EDB exploit
9.8
CVSSv3
CVE-2019-15260
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote malicious user to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected d...
Cisco Aironet 1540 Firmware
Cisco Aironet 1560 Firmware
Cisco Aironet 1800 Firmware
Cisco Aironet 2800 Firmware
Cisco Aironet 3800 Firmware
Cisco Aironet 4800 Firmware
NA
CVE-2005-1817
Invision Power Board (IPB) 1.0 up to and including 1.3 allows remote malicious users to edit arbitrary forum posts via a direct request to index.php with modified parameters.
Invision Power Services Invision Board 1.3
Invision Power Services Invision Board 1.1.1
Invision Power Services Invision Board 1.2
Invision Power Services Invision Board 1.0
Invision Power Services Invision Board 1.1.2
Invision Power Services Invision Board 1.3 Final
Invision Power Services Invision Board 1.0.1
1 EDB exploit
NA
CVE-2001-0567
Digital Creations Zope 2.3.2 and previous versions allows a local malicious user to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.
Zope Zope 7.1
Zope Zope 7.2
NA
CVE-2006-1213
JiRo's Banner System Experience and Professional 1.0 and previous versions allows remote malicious users to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new ad...
Jiro Banner System 1.0 Professional
Jiro Banner System 1.0 Experience
1 EDB exploit
NA
CVE-2003-0162
Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote malicious users to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.
Ecartis Ecartis 1.0.0 Snapshot 2002-10-13
NA
CVE-2002-2169
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote malicious users to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" t...
Aol Instant Messenger 4.5
Aol Instant Messenger 4.7
Aol Instant Messenger 4.7.2480
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »