Latest CVE Feed
-
8.8
HIGHCVE-2016-10949
The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.... Read more
Affected Products : relevanssi- EPSS Score: %0.59
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2016-10948
The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.... Read more
Affected Products : post_indexer- EPSS Score: %0.84
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2016-10947
The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.... Read more
Affected Products : post_indexer- EPSS Score: %0.57
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10946
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.... Read more
Affected Products : wp-d3- EPSS Score: %0.11
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10945
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.... Read more
Affected Products : pagelines- EPSS Score: %0.20
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10944
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.... Read more
Affected Products : multisite_post_duplicator- EPSS Score: %0.20
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2016-10943
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.... Read more
Affected Products : zx-csv-upload- EPSS Score: %0.68
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10942
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.... Read more
Affected Products : podlove_podcast_publisher- EPSS Score: %0.98
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10941
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.... Read more
Affected Products : podlove_podcast_publisher- EPSS Score: %0.26
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2016-10940
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.... Read more
Affected Products : zm-gallery- EPSS Score: %14.10
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2016-10939
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.... Read more
Affected Products : xtremelocator- EPSS Score: %0.57
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-10938
The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.... Read more
Affected Products : copy-me- EPSS Score: %0.12
- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-10937
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.... Read more
- EPSS Score: %0.38
- Published: Sep. 08, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10936
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.... Read more
Affected Products : wp-polls- EPSS Score: %0.19
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10935
The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.... Read more
Affected Products : store_exporter_for_woocommerce- EPSS Score: %0.34
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10934
The check-email plugin before 0.5.2 for WordPress has XSS.... Read more
Affected Products : check_email- EPSS Score: %0.19
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2016-10933
An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the source code is downloaded over cleartext HTTP.... Read more
Affected Products : portaudio- EPSS Score: %0.24
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2016-10932
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.... Read more
- EPSS Score: %0.20
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2016-10931
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.... Read more
- EPSS Score: %0.18
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10930
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.... Read more
Affected Products : wp_support_plus_responsive_ticket_system- EPSS Score: %0.84
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024