Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2016-10992

    The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.... Read more

    Affected Products : music_store
    • EPSS Score: %0.26
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-10991

    The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.... Read more

    Affected Products : imdb-widget
    • EPSS Score: %0.60
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10990

    The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.... Read more

    • EPSS Score: %1.19
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10989

    The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.... Read more

    Affected Products : leenk.me
    • EPSS Score: %0.24
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10988

    The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, facebook_description, default_image, or _wp_http_referer.... Read more

    Affected Products : leenk.me
    • EPSS Score: %0.24
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10987

    The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.... Read more

    Affected Products : persian_woocommerce_sms
    • EPSS Score: %0.26
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10986

    The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.... Read more

    Affected Products : tweet_wheel
    • EPSS Score: %0.24
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10985

    The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.... Read more

    Affected Products : echo_sign
    • EPSS Score: %0.24
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10984

    The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.... Read more

    Affected Products : echo_sign
    • EPSS Score: %0.24
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10983

    The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.... Read more

    Affected Products : ghost
    • EPSS Score: %0.59
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10982

    The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.... Read more

    Affected Products : kento-post-view-counter
    • EPSS Score: %0.11
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10981

    The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_text, or kento_pvc_total_text.... Read more

    Affected Products : kento-post-view-counter
    • EPSS Score: %0.19
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10980

    The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.... Read more

    Affected Products : kento-post-view-counter
    • EPSS Score: %0.19
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10979

    The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS.... Read more

    Affected Products : tag_miner
    • EPSS Score: %0.19
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10978

    The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.... Read more

    Affected Products : tag_miner
    • EPSS Score: %0.11
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10977

    The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.... Read more

    Affected Products : nelio_ab_testing
    • EPSS Score: %0.48
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10976

    The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.... Read more

    Affected Products : safe_editor
    • EPSS Score: %2.44
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10975

    The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter.... Read more

    Affected Products : fluid-responsive-slideshow
    • EPSS Score: %0.19
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10974

    The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.... Read more

    Affected Products : fluid-responsive-slideshow
    • EPSS Score: %0.11
    • Published: Sep. 17, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10973

    The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter to BraftonAdminPage.php.... Read more

    Affected Products : brafton
    • EPSS Score: %1.32
    • Published: Sep. 16, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 291779 Results