Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2016-10774

    cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10773

    cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 3.3

    LOW
    CVE-2016-10772

    cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2016-10771

    cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10770

    cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10769

    cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10768

    cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-10767

    cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10766

    edx-platform before 2016-06-06 allows CSRF.... Read more

    Affected Products : edx-platform
    • Published: Jul. 29, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2016-10765

    edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.... Read more

    Affected Products : edx-platform
    • Published: Jul. 29, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10764

    In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so the ">" should be ">=" instead.... Read more

    Affected Products : linux_kernel
    • Published: Jul. 27, 2019
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2016-10763

    The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.... Read more

    Affected Products : camptix_event_ticketing
    • Published: Jul. 18, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-10762

    The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.... Read more

    Affected Products : camptix_event_ticketing
    • Published: Jul. 18, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10761

    Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.... Read more

    • Published: Jun. 29, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-10760

    On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.... Read more

    • Published: Jun. 11, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10759

    The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks .php uploads.... Read more

    Affected Products : precurio
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10758

    PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.... Read more

    Affected Products : phpkit
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10757

    In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.... Read more

    Affected Products : readaxo
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10756

    Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.... Read more

    Affected Products : kliqqi_cms
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10755

    AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.... Read more

    Affected Products : abantecart
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292822 Results