SEC Consult
94 exploits
Active since Dec 2005
ZTE Ox-330p Firmware - Information Disclosure
CVSS 7.5
SecurEnvoy SecurMail <9.2.501 - Path Traversal
CVSS 6.5
SecurEnvoy SecurMail <9.2.501 - Path Traversal
CVSS 8.1
SecurEnvoy SecurMail <9.2.501 - Info Disclosure
CVSS 6.5
SecurEnvoy SecurMail <9.2.501 - XSS
CVSS 6.1
SecurEnvoy SecurMail <9.2.501 - RCE
CVSS 9.1
SecurEnvoy SecurMail <9.2.501 - CSRF
CVSS 6.5
pimcore < 5.3.0 - SQL Injection via REST Web Service API
CVSS 6.5
pimcore < 5.3.0 - Cross-Site Request Forgery via Missing CSRF Token Validation
CVSS 8.8
WAGO e!DISPLAY 762-3000/3001/3002/3003 < FW 02 - Authenticated Arbitrary File Upload
CVSS 8.8
WAGO e!DISPLAY 762-3000/762-3001/762-3002/762-3003 < FW 02 - Authenticated Arbitrary File Write via WBM File Upload
CVSS 6.5
Ansible Tower <2.0.5 - Privilege Escalation
Aruba Airwave < 8.2.3.1 - XML External Entity Injection
CVSS 8.8
Novell Filr <1.2-2.0 - Privilege Escalation
CVSS 7.8
Novell Filr <1.2 SU3 & <2.0 SU2 - XSS
CVSS 5.4
Novell Filr <2.0 - Authenticated RCE
CVSS 8.8
Novell Filr < 2.0 - Cross-Site Request Forgery via Administrative Interface
CVSS 7.2
Yeager CMS 1.2.1 - Server-Side Request Forgery via dbhost Parameter
CVSS 7.2
Yeager CMS 1.2.1 - SQL Injection via pagedir_orderby Parameter
CVSS 8.8
Yeager CMS 1.2.1 - SQL Injection via Password Recovery UserEmail Parameter
CVSS 9.8
Yeager CMS 1.2.1 - SQL Injection via Password Reset Token Parameter
CVSS 9.8
Ansible Tower < 2.0.5 - Cross-Site Scripting via Multiple API Parameters
Yeager CMS 1.2.1 - Unrestricted File Upload
CVSS 7.8
Polycom RealPresence Resource Manager < 8.3.2 - Authenticated Directory Traversal and Arbitrary File Upload
CVSS 6.5
Polycom RealPresence Resource Manager < 8.3.2 - Session ID Info Disclosure & Privilege Escalation
CVSS 9.8