|
264371
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
|
CWE-20
Improper Input Validation
|
CVE-2016-9023
|
2024-11-21 12:00 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264372
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
|
CWE-20
Improper Input Validation
|
CVE-2016-9022
|
2024-11-21 12:00 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264373
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
|
CWE-20
Improper Input Validation
|
CVE-2016-9021
|
2024-11-21 12:00 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264374
|
5.4 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
|
CWE-79
Cross-site Scripting
|
CVE-2016-9271
|
2024-11-21 12:00 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264375
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.
|
CWE-74
Injection
|
CVE-2016-8900
|
2024-11-21 12:00 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264376
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
|
CWE-89
SQL Injection
|
CVE-2016-8898
|
2024-11-21 12:00 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264377
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
|
CWE-74
Injection
|
CVE-2016-8899
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264378
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
|
CWE-89
SQL Injection
|
CVE-2016-8897
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264379
|
9.8 |
CRITICAL
Network
|
b2evolution
|
b2evolution
|
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
|
CWE-74
Injection
|
CVE-2016-8901
|
2024-11-21 12:00 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264380
|
7.5 |
HIGH
Network
|
microfocus
|
netiq_edirectory
|
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9166
|
2024-11-21 12:00 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|