Latest CVE Feed
-
9.8
CRITICALCVE-2016-9051
An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause an out-of-bounds write resulting in memory corruption which can lead t... Read more
Affected Products : database_server- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9022
Exponent CMS before 2.6.0 has improper input validation in usersController.php.... Read more
Affected Products : exponent_cms- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-8954
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.... Read more
Affected Products : dashdb_local- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9005
IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.... Read more
Affected Products : system_storage_ts3100-ts3200_tape_library- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-3534
A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument password leads to sql injection. The ... Read more
Affected Products : church_management_system- Published: Apr. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-8898
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.... Read more
Affected Products : exponent_cms- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-8937
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to t... Read more
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8897
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.... Read more
Affected Products : exponent_cms- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3495
The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati... Read more
Affected Products :- Published: May. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-8899
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.... Read more
Affected Products : exponent_cms- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3535
A vulnerability, which was classified as critical, was found in Campcodes Church Management System 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument password leads to sql injection. It is possible to initiate... Read more
Affected Products : church_management_system- Published: Apr. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3465
A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been classified as critical. Affected is the function laporan_filter of the file /application/controller/Transaki.php. The manipulation of the argument dari/sampai leads to ... Read more
Affected Products : laundry_shop_management_system- Published: Apr. 08, 2024
- Modified: Jan. 17, 2025
-
9.8
CRITICALCVE-2024-3457
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The manipulation of the argument GroupId leads to sql injection. It is ... Read more
- Published: Apr. 08, 2024
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2024-3458
A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation of the argument TunnelId leads to sql injection. The attack c... Read more
- Published: Apr. 08, 2024
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2016-8859
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.... Read more
Affected Products : musl- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-3486
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution. ... Read more
Affected Products : imanager- Published: May. 15, 2024
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2016-8901
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.... Read more
Affected Products : b2evolution- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3424
A vulnerability classified as critical has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file admin/listscore.php. The manipulation of the argument title leads to sql injection. It is possible to launch the att... Read more
Affected Products : online_courseware- Published: Apr. 07, 2024
- Modified: Jan. 17, 2025
-
9.8
CRITICALCVE-2017-20149
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vu... Read more
Affected Products : routeros- Published: Oct. 15, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2024-3425
A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. Affected by this vulnerability is an unknown functionality of the file admin/activateall.php. The manipulation of the argument selector leads to sql injection. The a... Read more
Affected Products : online_courseware- Published: Apr. 07, 2024
- Modified: Jan. 17, 2025