Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2016-10896

    The seo-redirection plugin before 4.3 for WordPress has stored XSS.... Read more

    Affected Products : seo_redirection
    • Published: Aug. 21, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10895

    The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.... Read more

    Affected Products : optiontree
    • Published: Aug. 20, 2019
    • Modified: Nov. 21, 2024
  • 4.6

    MEDIUM
    CVE-2016-10894

    xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse c... Read more

    Affected Products : debian_linux xtrlock
    • Published: Aug. 16, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10893

    The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.... Read more

    Affected Products : crayon_syntax_highlighter
    • Published: Aug. 20, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10892

    The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.... Read more

    Affected Products : chained_quiz
    • Published: Aug. 20, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10891

    The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.... Read more

    Affected Products : activity_log
    • Published: Aug. 21, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10890

    The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.... Read more

    Affected Products : activity_log
    • Published: Aug. 21, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10889

    The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.... Read more

    Affected Products : nextgen_gallery
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10888

    The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.... Read more

    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10887

    The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.... Read more

    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10886

    The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.... Read more

    Affected Products : wp_editor
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10885

    The wp-editor plugin before 1.2.6 for WordPress has CSRF.... Read more

    Affected Products : wp_editor
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10884

    The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.... Read more

    Affected Products : simple_membership
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10883

    The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.... Read more

    Affected Products : simple_add_pages_or_posts
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10882

    The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.... Read more

    Affected Products : google_doc_embedder
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10881

    The google-document-embedder plugin before 2.6.2 for WordPress has XSS.... Read more

    Affected Products : google_doc_embedder
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10880

    The google-document-embedder plugin before 2.6.1 for WordPress has XSS.... Read more

    Affected Products : google_doc_embedder
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10879

    The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.... Read more

    Affected Products : live_chat
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10877

    The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.... Read more

    Affected Products : wp_editor wp_editor
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10876

    The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.... Read more

    Affected Products : wp_database_backup
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292803 Results