Search Results (29417 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-1000497 1 Pepperminty-wiki Project 1 Pepperminty-wiki 2024-11-21 9.8 Critical
Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution
CVE-2017-1000487 3 Codehaus-plexus, Debian, Redhat 4 Plexus-utils, Debian Linux, Jboss Amq and 1 more 2024-11-21 9.8 Critical
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
CVE-2017-0359 2 Debian, Reproducible Builds 2 Debian Linux, Diffoscope 2024-11-21 9.8 Critical
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
CVE-2016-9652 2 Google, Redhat 2 Chrome, Rhel Extras 2024-11-21 9.8 Critical
Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.
CVE-2016-9063 3 Debian, Mozilla, Python 3 Debian Linux, Firefox, Python 2024-11-21 9.8 Critical
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVE-2016-9026 1 Exponentcms 1 Exponent Cms 2024-11-21 9.8 Critical
Exponent CMS before 2.6.0 has improper input validation in fileController.php.
CVE-2016-9025 1 Exponentcms 1 Exponent Cms 2024-11-21 9.8 Critical
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
CVE-2016-9023 1 Exponentcms 1 Exponent Cms 2024-11-21 9.8 Critical
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
CVE-2016-9022 1 Exponentcms 1 Exponent Cms 2024-11-21 9.8 Critical
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
CVE-2016-9021 1 Exponentcms 1 Exponent Cms 2024-11-21 9.8 Critical
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
CVE-2016-8717 1 Moxa 2 Awk-3131a, Awk-3131a Firmware 2024-11-21 9.8 Critical
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.
CVE-2016-7398 1 Php 1 Ext-http 2024-11-21 9.8 Critical
A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.
CVE-2016-7063 1 Pritunl 1 Pritunl-client 2024-11-21 9.8 Critical
A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.
CVE-2016-6918 1 Lexmark 1 Markvision Enterprise 2024-11-21 9.8 Critical
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
CVE-2016-6813 1 Apache 1 Cloudstack 2024-11-21 9.8 Critical
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.
CVE-2016-5202 5 Apple, Google, Linux and 2 more 5 Macos, Chrome, Linux Kernel and 2 more 2024-11-21 9.1 Critical
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
CVE-2016-5194 2 Google, Redhat 2 Chrome, Rhel Extras 2024-11-21 9.8 Critical
Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
CVE-2016-4991 1 Nodepdf Project 1 Nodepdf 2024-11-21 9.8 Critical
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.
CVE-2016-4606 2 Apple, Haxx 2 Mac Os X, Curl 2024-11-21 9.8 Critical
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.
CVE-2016-4401 1 Arubanetworks 1 Clearpass 2024-11-21 9.8 Critical
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.