|
266771
|
4.6 |
MEDIUM
Physics
|
google
|
android
|
An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending an AT command over USB. The Samsung ID is SVE-2015-5301 (June 2016).
|
CWE-287
Improper Authentication
|
CVE-2016-11041
|
2024-11-21 11:45 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266772
|
9.8 |
CRITICAL
Network
|
odata4j_project
|
odata4j
|
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
|
CWE-89
SQL Injection
|
CVE-2016-11024
|
2024-11-21 11:45 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266773
|
9.8 |
CRITICAL
Network
|
odata4j_project
|
odata4j
|
odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
|
CWE-89
SQL Injection
|
CVE-2016-11023
|
2024-11-21 11:45 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266774
|
7.2 |
HIGH
Network
|
netgear
|
prosafe_wc9500_firmware prosafe_wc7600_firmware prosafe_wc7520_firmware
|
NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login…
|
CWE-78
OS Command
|
CVE-2016-11022
|
2024-11-21 11:45 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266775
|
6.5 |
MEDIUM
Network
|
zohocorp
|
manageengine_password_manager_pro
|
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
|
CWE-200
Information Exposure
|
CVE-2016-1159
|
2024-11-21 11:45 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266776
|
7.2 |
HIGH
Network
|
dlink
|
dcs-930l_firmware
|
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
|
CWE-78
OS Command
|
CVE-2016-11021
|
2024-11-21 11:45 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266777
|
9.8 |
CRITICAL
Network
|
kunena
|
kunena
|
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-11020
|
2024-11-21 11:45 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266778
|
9.8 |
CRITICAL
Network
|
huge-it
|
image_gallery
|
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gal…
|
CWE-89
SQL Injection
|
CVE-2016-11018
|
2024-11-21 11:45 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266779
|
9.8 |
CRITICAL
Network
|
akips
|
network_monitor
|
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a …
|
CWE-78
OS Command
|
CVE-2016-11017
|
2024-11-21 11:45 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266780
|
6.1 |
MEDIUM
Network
|
netgear
|
jnr1010_firmware
|
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11016
|
2024-11-21 11:45 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|