|
258111
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
|
CWE-20
Improper Input Validation
|
CVE-2016-9021
|
2024-11-21 12:00 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258112
|
5.4 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
|
CWE-79
Cross-site Scripting
|
CVE-2016-9271
|
2024-11-21 12:00 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258113
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.
|
CWE-74
Injection
|
CVE-2016-8900
|
2024-11-21 12:00 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258114
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
|
CWE-89
SQL Injection
|
CVE-2016-8898
|
2024-11-21 12:00 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258115
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
|
CWE-74
Injection
|
CVE-2016-8899
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258116
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
|
CWE-89
SQL Injection
|
CVE-2016-8897
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258117
|
9.8 |
CRITICAL
Network
|
b2evolution
|
b2evolution
|
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
|
CWE-74
Injection
|
CVE-2016-8901
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258118
|
7.5 |
HIGH
Network
|
microfocus
|
netiq_edirectory
|
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9166
|
2024-11-21 12:00 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258119
|
7.8 |
HIGH
Local
|
mozilla
|
firefox
|
A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
|
CWE-416
Use After Free
|
CVE-2016-9069
|
2024-11-21 12:00 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258120
|
8.8 |
HIGH
Network
|
processmaker
|
processmaker
|
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being execu…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-9045
|
2024-11-21 12:00 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|