Latest CVE Feed
-
9.8
CRITICALCVE-2016-2359
Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.... Read more
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2356
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.... Read more
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2355
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.... Read more
Affected Products : dotcms- Published: Dec. 19, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2403
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.... Read more
Affected Products : symfony- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2337
Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.... Read more
Affected Products : ruby- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2173
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.... Read more
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2170
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.... Read more
- Published: Apr. 12, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2339
An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed ob... Read more
Affected Products : ruby- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2000
HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.... Read more
- Published: Apr. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-20005
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more
Affected Products : rest\/json- Published: Jan. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2024
HPE Insight Control before 7.5.1 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.... Read more
- Published: Jun. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-20002
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more
Affected Products : rest\/json- Published: Jan. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2003
HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collectio... Read more
Affected Products : p9000_command_view_advanced_edition_software xp7_command_view_advanced_edition_suite- Published: Apr. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-3347
A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file activate_jet_details_form_handler.php. The manipulation of the argument jet_id leads t... Read more
Affected Products : airline_ticket_reservation_system- Published: Apr. 05, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2016-20017
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.... Read more
- Actively Exploited
- Published: Oct. 19, 2022
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2016-2031
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive... Read more
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1925
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.... Read more
Affected Products : lha_for_unix- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-20009
A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
Affected Products : vxworks sgt-100_firmware sgt-200_firmware sgt-300_firmware sgt-400_firmware sgt-a20_firmware sgt-a35_firmware sgt-a65_firmware sgt-100 sgt-200 +5 more products- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28962
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Junipe... Read more
Affected Products : junos- Published: Apr. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32207
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire macos element_software h300s_firmware h500s_firmware h700s_firmware +9 more products- Published: Jul. 07, 2022
- Modified: Apr. 23, 2025