|
211421
|
8.8 |
HIGH
Network
|
imagely
|
nextgen_gallery
|
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-9228
|
2024-11-21 11:40 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211422
|
7.2 |
HIGH
Network
|
alegrocart
|
alegrocart
|
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL i…
|
CWE-94
Code Injection
|
CVE-2015-9227
|
2024-11-21 11:40 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211423
|
7.2 |
HIGH
Network
|
alegrocart
|
alegrocart
|
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_fi…
|
CWE-89
SQL Injection
|
CVE-2015-9226
|
2024-11-21 11:40 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211424
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_server_2016 windows_8.1 windows_server_2008 windows_vista
|
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0026
|
2024-11-21 11:40 |
2016-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211425
|
5.5 |
MEDIUM
Local
|
microsoft
|
outlook_web_access
|
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements…
|
CWE-200
Information Exposure
|
CVE-2016-0028
|
2024-11-21 11:40 |
2016-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211426
|
7.3 |
HIGH
Local
|
microsoft
|
word word_for_mac office_web_apps sharepoint_server office office_web_apps_server office_compatibility_pack office_online_server
|
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation …
|
CWE-20
Improper Input Validation
|
CVE-2016-0025
|
2024-11-21 11:40 |
2016-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211427
|
7.8 |
HIGH
Local
|
microsoft
|
infopath
|
Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0021
|
2024-11-21 11:40 |
2016-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211428
|
7.8 |
HIGH
Local
|
microsoft
|
word word_for_mac office office_web_apps_server sharepoint_server office_compatibility_pack word_viewer
|
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0052
|
2024-11-21 11:40 |
2016-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211429
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0051
|
2024-11-21 11:40 |
2016-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211430
|
5.3 |
MEDIUM
Network
|
microsoft
|
windows_server_2012 windows_server_2008
|
Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS …
|
CWE-20
Improper Input Validation
|
CVE-2016-0050
|
2024-11-21 11:40 |
2016-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|