Latest CVE Feed
-
6.1
MEDIUMCVE-2016-15029
A vulnerability has been found in Ydalb mapicoin up to 1.9.0 and classified as problematic. This vulnerability affects unknown code of the file webroot/stats.php. The manipulation of the argument link/search leads to cross site scripting. The attack can b... Read more
Affected Products : mapicoin- EPSS Score: %0.06
- Published: Mar. 21, 2023
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2016-15028
A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation leads to improper... Read more
Affected Products : rest_api- EPSS Score: %0.03
- Published: Mar. 12, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-15027
A vulnerability was found in meta4creations Post Duplicator Plugin 2.18 on WordPress. It has been classified as problematic. Affected is the function mtphr_post_duplicator_notice of the file includes/notices.php. The manipulation of the argument post-dupl... Read more
Affected Products : post_duplicator- EPSS Score: %0.16
- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2016-15026
A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. An attack has to be approached locally. Upgrading to version 1... Read more
Affected Products : dd-plist- EPSS Score: %0.06
- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-15025
A vulnerability, which was classified as problematic, was found in generator-hottowel 0.0.11. Affected is an unknown function of the file app/templates/src/server/_app.js of the component 404 Error Handler. The manipulation leads to cross site scripting. ... Read more
Affected Products : generator-hottowel- EPSS Score: %0.07
- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-15024
A vulnerability was found in doomsider shadow. It has been classified as problematic. Affected is an unknown function. The manipulation leads to denial of service. Attacking locally is a requirement. The complexity of an attack is rather high. The exploit... Read more
Affected Products : doomsider_shadow- EPSS Score: %0.02
- Published: Feb. 19, 2023
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-15023
A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affects an unknown part of the file getextension.php of the component Extension Handler. The manipulation leads to path traversal. Upgrading... Read more
Affected Products : application_server- EPSS Score: %0.09
- Published: Jan. 31, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-15022
A vulnerability was found in mosbth cimage up to 0.7.18. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file check_system.php. The manipulation of the argument $_SERVER['SERVER_SOFTWARE'] leads to cr... Read more
Affected Products : cimage- EPSS Score: %0.05
- Published: Jan. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15021
A vulnerability was found in nickzren alsdb. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. Upgrading to version v2 is able to address this issue. The identifier of the patch is cbc79a68... Read more
Affected Products : als_data_browser- EPSS Score: %0.04
- Published: Jan. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15020
A vulnerability was found in liftkit database up to 2.13.1. It has been classified as critical. This affects the function processOrderBy of the file src/Query/Query.php. The manipulation leads to sql injection. Upgrading to version 2.13.2 is able to addre... Read more
Affected Products : liftkit_database_library- EPSS Score: %0.05
- Published: Jan. 16, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-15019
A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposure of information through directory listing. The attack may be initiated rem... Read more
Affected Products : jekbox- EPSS Score: %0.11
- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15018
A vulnerability was found in krail-jpa up to 0.9.1. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. Upgrading to version 0.9.2 is able to address this issue. The identifier of the patch is c1e8486... Read more
Affected Products : krail-jpa- EPSS Score: %0.05
- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15017
A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileList of the file Classes/Service/UploadFileService.php. The manipulation leads to pathname traversal. Upgrad... Read more
Affected Products : media_upload- EPSS Score: %0.09
- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15016
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to versi... Read more
Affected Products : joomla_mod_einsatz_stats- EPSS Score: %0.05
- Published: Jan. 08, 2023
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-15015
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexit... Read more
Affected Products : barzahlen_payment_module_php_sdk- EPSS Score: %0.10
- Published: Jan. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-15014
A vulnerability has been found in CESNET theme-cesnet up to 1.x on ownCloud and classified as problematic. Affected by this vulnerability is an unknown functionality of the file cesnet/core/lostpassword/templates/resetpassword.php. The manipulation leads ... Read more
Affected Products : theme-cesnet- EPSS Score: %0.03
- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15013
A vulnerability was found in ForumHulp searchresults. It has been rated as critical. Affected by this issue is the function list_keywords of the file event/listener.php. The manipulation of the argument word leads to sql injection. The name of the patch i... Read more
Affected Products : search_results- EPSS Score: %0.04
- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15012
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in forcedotcom SalesforceMobileSDK-Windows up to 4.x. It has been rated as critical. This issue affects the function ComputeCountSql of the file SalesforceSDK/SmartStore/Store/QuerySpec.cs. The man... Read more
Affected Products : mobile_software_development_kit- EPSS Score: %0.05
- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-15011
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse of the file dssp-client/src/main/java/be/e_contract/dssp/client/SignResponseVerifier.java. The manipulatio... Read more
Affected Products : dssp- EPSS Score: %0.09
- Published: Jan. 06, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-15010
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in University of Cambridge django-ucamlookup up to 1.9.1. Affected by this vulnerability is an unknown functionality of the component Lookup Handler. The manipulation lead... Read more
Affected Products : django-ucamlookup- EPSS Score: %0.08
- Published: Jan. 05, 2023
- Modified: Nov. 21, 2024