CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “ami”

199 vulnerabilities found for “ami”

Page 1 of 10

CVE-2024-45675
HIGH8.4

IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.

ibm / informix_dynamic_server
Local
Published Dec 2, 2025
Page 1 of 10
CVE-2025-11736
HIGH7.3

A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

angeljudesuarez / online_examination_system
Network
Published Oct 14, 2025
CVE-2025-40594
MEDIUM6.3

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

siemens / sinamics_g220_firmware+4
Local
Published Sep 9, 2025
CVE-2024-49342
HIGH7.5

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

ibm / informix_dynamic_server+1
Network
Published Jul 28, 2025
CVE-2024-49343
MEDIUM5.4

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

ibm / informix_dynamic_server+1
Network
Published Jul 28, 2025
CVE-2025-1991
HIGH7.5

IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets.

ibm / informix_dynamic_server+2
Network
Published Jun 28, 2025
CVE-2023-28523
HIGH8.4

IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753.

ibm / informix_dynamic_server+2
Local
Published Dec 9, 2023
CVE-2023-28526
MEDIUM6.2

IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204.

ibm / informix_dynamic_server+2
Local
Published Dec 9, 2023
CVE-2023-28527
MEDIUM6.2

IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206.

ibm / informix_dynamic_server+2
Local
Published Dec 9, 2023
CVE-2021-3439
HIGH7.8

HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.

hp / 340_g3_firmware+376
Local
Published Feb 1, 2023
CVE-2021-20515
MEDIUM6.7

IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.

ibm / informix_dynamic_server
Local
Published Apr 30, 2021
CVE-2020-4799
HIGH7.8

IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds write vulnerability. IBM X-Force ID: 189460.

ibm / informix_dynamic_server
Local
Published Oct 8, 2020
CVE-2019-11457
HIGH8.8

Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.

micropyramid / django_crm
Network
Published Aug 27, 2019
CVE-2018-1636
MEDIUM6.7

Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144441.

ibm / informix_dynamic_server+11
Local
Published Aug 20, 2019
CVE-2018-1635
MEDIUM6.7

Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144439.

ibm / informix_dynamic_server+11
Local
Published Aug 20, 2019
CVE-2018-1634
MEDIUM6.7

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.

ibm / informix_dynamic_server+11
Local
Published Aug 20, 2019
CVE-2019-3800
MEDIUM6.3

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

pivotal / cloud_foundry_command_line_interface+59
Local
Published Aug 5, 2019
CVE-2018-0438
HIGH7.8

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system permissions, which could allow non-administrative users to place files within restricted directories. An attacker could exploit this vulnerability by placing an executable file within the restricted directory, which when executed by the ERC client, would run with Administrator privileges.

cisco / umbrella_enterprise_roaming_client
Local
Published Oct 5, 2018
CVE-2018-0437
HIGH7.8

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system permissions, which could allow non-administrative users to place files within restricted directories. An attacker could exploit this vulnerability by placing an executable file within the restricted directory, which when executed by the ERC client, would run with Administrator privileges.

cisco / umbrella_enterprise_roaming_client+2
Local
Published Oct 5, 2018
CVE-2018-16552
HIGH8.8

MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.

micropyramid / django_crm
Network
Published Sep 5, 2018