Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-01-12 CVE-2017-5346 SQL Injection vulnerability in Genixcms 0.0.8
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
network
low complexity
genixcms CWE-89
7.2
2017-01-12 CVE-2017-5345 SQL Injection vulnerability in Metalgenix Genixcms 0.0.8
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.
network
low complexity
metalgenix CWE-89
8.8
2017-01-12 CVE-2016-9444 Improper Input Validation vulnerability in ISC Bind
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
network
low complexity
isc CWE-20
7.5
2017-01-12 CVE-2016-9147 Improper Input Validation vulnerability in ISC Bind 9.10.4/9.11.0/9.9.9
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
network
low complexity
isc CWE-20
7.5
2017-01-12 CVE-2016-9131 Improper Input Validation vulnerability in multiple products
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
network
low complexity
isc debian redhat netapp CWE-20
7.5
2017-01-11 CVE-2016-6820 Information Exposure vulnerability in Netapp Metrocluster Tiebreaker 1.1
MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauthenticated user.
network
low complexity
netapp CWE-200
7.5
2017-01-11 CVE-2016-4808 Cross-Site Request Forgery (CSRF) vulnerability in Web2Py
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.
network
low complexity
web2py CWE-352
8.8
2017-01-11 CVE-2016-4806 Information Exposure vulnerability in Web2Py
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.
network
low complexity
web2py CWE-200
7.5
2017-01-11 CVE-2016-7478 Unspecified vulnerability in PHP
Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.
network
low complexity
php
7.5
2017-01-11 CVE-2017-2967 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the XFA engine related to a form's structure and organization.
local
low complexity
adobe CWE-119
7.8