|
269141
|
8.8 |
HIGH
Network
|
abantecart
|
abantecart
|
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pag…
|
CWE-89
SQL Injection
|
CVE-2016-10755
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269142
|
8.8 |
HIGH
Network
|
vtiger
|
vtiger_crm
|
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
|
CWE-89
SQL Injection
|
CVE-2016-10754
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269143
|
8.8 |
HIGH
Network
|
e107
|
e107
|
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-10753
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269144
|
9.8 |
CRITICAL
Network
|
s9y
|
serendipity
|
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated b…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10752
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269145
|
7.2 |
HIGH
Network
|
osclass
|
osclass
|
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PH…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10751
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269146
|
8.1 |
HIGH
Network
|
hazelcast
|
hazelcast
|
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinReques…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-10750
|
2024-11-21 11:44 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269147
|
6.1 |
MEDIUM
Network
|
tp-link
|
archer_cr700_firmware
|
TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contai…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10719
|
2024-11-21 11:44 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269148
|
9.8 |
CRITICAL
Network
|
cjson_project
|
cjson
|
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10749
|
2024-11-21 11:44 |
2019-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269149
|
7.5 |
HIGH
Network
|
redhat debian
|
libvirt debian_linux
|
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability…
|
CWE-254
7PK - Security Features
|
CVE-2016-10746
|
2024-11-21 11:44 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269150
|
8.6 |
HIGH
Network
|
palletsprojects
|
jinja
|
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2016-10745
|
2024-11-21 11:44 |
2019-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|