Latest CVE Feed
-
9.8
CRITICALCVE-2016-7789
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7788
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7784
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7783
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7782
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7781
SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7780
SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7140
Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : plone- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7139
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : plone- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7138
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : plone- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7137
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2... Read more
Affected Products : plone- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7136
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.... Read more
Affected Products : plone- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2016-7135
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceedito... Read more
Affected Products : plone- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6522
Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6350
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6255
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6247
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2016-6246
OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) device name of the root node.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6245
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6243
thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025