Latest CVE Feed
-
9.8
CRITICALCVE-2024-3817
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.... Read more
- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9138
PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exc... Read more
Affected Products : php- EPSS Score: %2.02
- Published: Jan. 04, 2017
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-3770
A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage-courses.php?del=1. The manipulation of the argument del leads to sql injecti... Read more
Affected Products : student_record_system- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9137
Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that ... Read more
Affected Products : php- EPSS Score: %0.89
- Published: Jan. 04, 2017
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-9157
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.... Read more
Affected Products : sicam_pas\/pqs- EPSS Score: %1.46
- Published: Dec. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-3740
A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file /adminPage/conf/reload. The manipulation of the argument nginxExe leads to deserialization. The attack ma... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2017-7658
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chun... Read more
Affected Products : debian_linux hci_management_node solidfire snapcenter e-series_santricity_os_controller e-series_santricity_web_services snapmanager retail_xstore_point_of_service jetty snap_creator_framework +10 more products- EPSS Score: %9.39
- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3691
A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the component Registration Page. The manipulation leads to sql injection. The attack may be launched rem... Read more
Affected Products : small_crm- Published: Apr. 12, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2016-9023
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.... Read more
Affected Products : exponent_cms- EPSS Score: %0.61
- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9054
An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_list_by_set_binid re... Read more
Affected Products : database_server- EPSS Score: %19.25
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9081
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.... Read more
Affected Products : joomla\!- EPSS Score: %0.21
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9013
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the databas... Read more
- EPSS Score: %2.72
- Published: Dec. 09, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-9075
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This... Read more
Affected Products : firefox- EPSS Score: %3.30
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3584
qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoint. By manipulating the `name` parameter through URL encoding, an attacker can upload a file to an arbitra... Read more
Affected Products : qdrant- Published: May. 30, 2024
- Modified: Jul. 10, 2025
-
9.8
CRITICALCVE-2016-9051
An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause an out-of-bounds write resulting in memory corruption which can lead t... Read more
Affected Products : database_server- EPSS Score: %4.25
- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9022
Exponent CMS before 2.6.0 has improper input validation in usersController.php.... Read more
Affected Products : exponent_cms- EPSS Score: %0.61
- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-8954
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.... Read more
Affected Products : dashdb_local- EPSS Score: %0.91
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9005
IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.... Read more
Affected Products : system_storage_ts3100-ts3200_tape_library- EPSS Score: %0.49
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-3534
A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument password leads to sql injection. The ... Read more
Affected Products : church_management_system- Published: Apr. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-8898
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.... Read more
Affected Products : exponent_cms- EPSS Score: %0.26
- Published: May. 24, 2019
- Modified: Nov. 21, 2024