SEC Consult
94 exploits
Active since Dec 2005
Polycom RealPresence Resource Manager < 8.3.2 - Authenticated Installation Path Exposure via JConfigManager
CVSS 6.5
Polycom RealPresence Resource Manager < 8.3.2 - Unspecified Impact via Weak Passwords
CVSS 7.8
Apache Struts <2.3.1.1 - Code Injection
Apache Struts < 2.3.1.1 - Remote Code Execution via CookieInterceptor
Apache Struts < 2.2.3.1 - Remote Code Execution via ExceptionDelegator OGNL Expression Injection
CVSS 9.8
Aruba Airwave < 8.2.3.1 - Reflected Cross-Site Scripting in VisualRF Component
CVSS 6.1
RSA Enterprise Compromise Assessment Tool 4.1.0.1 - XML External Entity Injection
Oracle Fusion Middleware WebCenter Sites 7.6.2, 11.1.1.6.0, 11.1.1.6.1 - Authenticated Integrity Impact
SonicWALL GLobal VPN Client <4.0.0.810 - RCE
Oracle Java SE <7.17,6.43,5.41 - DoS
Zeta Producer Desktop CMS < 14.2.1 - Unauthenticated Remote Code Execution via PHP File Upload
CVSS 9.8
Zend Framework 1.x < 1.11.12 and 1.12.x < 1.12.0 - XML External Entity Injection via XML-RPC Request
CVSS 9.1
Rejected
WordPress Core 3.1.3 - SQL Injection
WAGO e!DISPLAY 762-3000-762-3003 < FW 02 - Cross-Site Scripting via Web Server Request
CVSS 5.4
WebTitan < 4.01 - SQL Injection via categories-x.php sortkey Parameter
WD Arkeia Virtual Appliance Firmware < 10.2.7 - Path Traversal and Remote Code Execution via Lang Cookie Parameter
Symantec Web Gateway < 5.1.1 - OS Command Injection via Management Console
Shopizer < 1.1.5 - Cross-Site Scripting via Multiple Parameters
pimcore < 5.2.3 and >=0 < 5.3.0 - Cross-Site Scripting via Multiple Input Fields
CVSS 5.4
OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
OpenProject 5.0.0-8.3.1 - SQL Injection via Activities API ID Parameter
CVSS 8.1
Magento eCommerce - Local File Disclosure
LimeSurvey < 3.17.14 - Reflected Cross-Site Scripting in Survey_Common_Action.php
CVSS 5.4