CNA 2016

VulDB is an officially certified CVE Numbering Authority (CNA) by MITRE and Authorized Data Publisher (ADP) by NIST NVD. We are authorized to handle new vulnerability submissions, assign unique CVEs and disclose them. CVE is an international program to discover vulnerabilities which are then assigned and published to the CVE list. Partners coordinate such CVE entries to communicate consistent descriptions. Information technology and cybersecurity professionals all around the world use CVE records to ensure they are discussing the same issues, and to coordinate their efforts to prioritize and address these properly.

Vendor

Identifying all affected vendors is a good starting point for an overview. This makes it possible to determine an homogeneous landscape or the most important hotspots in heterogeneous landscapes.

Product

NUUO NVRmini 21
go4rayyan Scumblr1
Deis Workflow Manager1
Doc2k RE-Chat1
Dynacase Webdesk1

Grouping vulnerabilities by products helps to get an overview. This makes it possible to determine an homogeneous landscape or the most important hotspots in heterogeneous landscapes.

Remediation

Official Fix32
Temporary Fix0
Workaround0
Unavailable1
Not Defined2

Vendors and researchers are eager to find countermeasures to mitigate security vulnerabilities. These can be distinguished between multiple forms and levels of remediation which influence risks differently.

Exploitability

High0
Functional0
Proof-of-Concept2
Unproven0
Not Defined33

Researcher and attacker which are looking for security vulnerabilities try to exploit them for academic purposes or personal gain. The level and quality of exploitability can be distinguished to determine simplicity and strength of attacks.

Access Vector

Not Defined0
Physical0
Local3
Adjacent13
Network19

The approach a vulnerability it becomes important to use the expected access vector. This is typically via the network, local, or physically even.

Authentication

Not Defined0
High2
Low27
None6

To exploit a vulnerability a certail level of authentication might be required. Vulnerabilities without such a requirement are much more popular.

User Interaction

Not Defined0
Required11
None24

Some attack scenarios require some user interaction by a victim. This is typical for phishing, social engineering and cross site scripting attacks.

VulDB

≤10
≤21
≤33
≤412
≤53
≤611
≤72
≤83
≤90
≤100

The moderation team is always defining the base vector and base score for an entry. These and all other available scores are used to generate the meta score.

Exploit 0-day

<1k7
<2k25
<5k3
<10k0
<25k0
<50k0
<100k0
≥100k0

The moderation team is working with the threat intelligence team to determine prices for exploits. Our unique algorithm is used to identify the 0-day prices for an exploit, before it got distributed or became public. Calculated prices are aligned to prices disclosed by vulnerability broker and compared to prices we see on exploit markets.

IDVulnerabilityScopeResponsibleSubmissionCreatedUpdatedCVESubmitCNA
258780NUUO NVRmini 2 deletefile.php path traversalVulDBVulDB03/30/202403/30/2024CVE-2016-15038
 
accepted
251570go4rayyan Scumblr Task cross site scriptingVulDBVulDB01/19/202402/15/2024CVE-2016-15037
 
accepted
248847Deis Workflow Manager race conditionVulDBVulDB12/22/202301/18/2024CVE-2016-15036
 
accepted
238155Doc2k RE-Chat re_chat.js cross site scriptingVulDBVulDB08/26/202309/20/2023CVE-2016-15035
 
accepted
233366Dynacase Webdesk freedomrss_search.php freedomrss_search sql injectionVulDBVulDB07/08/202307/26/2023CVE-2016-15034
 
accepted
230391mback2k mh_httpbl Extension class.tx_mhhttpbl.php stopOutput cross site scriptingVulDBVulDB05/31/202306/25/2023CVE-2016-15032
 
accepted
228022PHP-Login POST Parameter class.loginscript.php checkLogin sql injectionVulDBVulDB05/04/202305/27/2023CVE-2016-15031
 
accepted
223803Arno0x TwoFactorAuth login.php redirectVulDBVulDB03/24/202304/14/2023CVE-2016-15030
 
accepted
223402Ydalb mapicoin stats.php cross site scriptingVulDBVulDB03/19/202304/12/2023CVE-2016-15029
 
accepted
222847ICEPAY REST-API-NET Checksum Validation RestClient.cs RestClient integrity checkVulDBVulDB03/11/202304/04/2023CVE-2016-15028
 
accepted
221496meta4creations Post Duplicator Plugin notices.php mtphr_post_duplicator_notice cross site scriptingVulDBVulDB02/19/202303/23/2023CVE-2016-15027
 
accepted
2214863breadt dd-plist xml external entity referenceVulDBVulDB02/18/202303/23/2023CVE-2016-15026
 
accepted
221484generator-hottowel 404 Error _app.js cross site scriptingVulDBVulDB02/18/202303/23/2023CVE-2016-15025
 
accepted
221478doomsider shadow denial of serviceVulDBVulDB02/18/202303/23/2023CVE-2016-15024
 
accepted
219765SiteFusion Application Server Extension getextension.php path traversalVulDBVulDB01/30/202302/25/2023CVE-2016-15023
 
accepted
219715mosbth cimage check_system.php cross site scriptingVulDBVulDB01/28/202302/25/2023CVE-2016-15022
 
accepted
218429nickzren alsdb sql injectionVulDBVulDB01/16/202302/08/2023CVE-2016-15021
 
accepted
218391liftkit database Query.php processOrderBy sql injectionVulDBVulDB01/15/202302/07/2023CVE-2016-15020
 
accepted
218375tombh jekbox server.rb exposure of information through directory listingVulDBVulDB01/14/202302/07/2023CVE-2016-15019
 
accepted
218373krail-jpa sql injectionVulDBVulDB01/14/202302/07/2023CVE-2016-15018
 
accepted
217786fabarea media_upload UploadFileService.php getUploadedFileList pathname traversalVulDBVulDB01/10/202301/31/2023CVE-2016-15017
 
accepted
217653mrtnmtth joomla_mod_einsatz_stats helper.php getStatsByType sql injectionVulDBVulDB01/08/202301/30/2023CVE-2016-15016
 
accepted
217650viafintech Barzahlen Payment Module PHP SDK Webhook.php verify timing discrepancyVulDBVulDB01/08/202301/30/2023CVE-2016-15015
 
accepted
217633CESNET theme-cesnet resetpassword.php insufficiently protected credentialsVulDBVulDB01/07/202301/30/2023CVE-2016-15014
 
accepted
217628ForumHulp searchresults listener.php list_keywords sql injectionVulDBVulDB01/07/202301/30/2023CVE-2016-15013
 
accepted
217619forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injectionVulDBVulDB01/07/202301/29/2023CVE-2016-15012
 
accepted
217549e-Contract dssp SignResponseVerifier.java checkSignResponse xml external entity referenceVulDBVulDB01/06/202301/29/2023CVE-2016-15011
 
accepted
217441University of Cambridge django-ucamlookup Lookup cross site scriptingVulDBVulDB01/05/202301/28/2023CVE-2016-15010
 
accepted
217440OpenACS bug-tracker Search nav-bar.adp cross-site request forgeryVulDBVulDB01/05/202301/28/2023CVE-2016-15009
 
accepted
217355oxguy3 coebot-www channel.js showChannelBoir cross site scriptingVulDBVulDB01/04/202301/28/2023CVE-2016-15008
 
accepted
217195Centralized-Salesforce-Dev-Framework SOQL SObjectService.cls SObjectService injectionVulDBVulDB01/02/202301/27/2023CVE-2016-15007
 
accepted
217181enigmaX Scrambling Table main.c getSeed prng seedVulDBVulDB01/02/202301/26/2023CVE-2016-15006
 
accepted
98355MONyog Ultimate Cookie privileges managementVulDBVulDB03/21/201703/22/201711/14/2022CVE-2016-1500222
accepted
97204FileZilla Client Installer uninstall.exe unquoted search pathVulDBVulDB02/22/201707/16/2022CVE-2016-15003
 
accepted
96073InfiniteWP Client Plugin injectionVulDBVulDB01/27/201711/04/2022CVE-2016-15004
 
accepted

Interested in the pricing of exploits?

See the underground prices here!