Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2016-10768

    cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-10767

    cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).... Read more

    Affected Products : cpanel
    • Published: Aug. 05, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10766

    edx-platform before 2016-06-06 allows CSRF.... Read more

    Affected Products : edx-platform
    • Published: Jul. 29, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2016-10765

    edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.... Read more

    Affected Products : edx-platform
    • Published: Jul. 29, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10764

    In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so the ">" should be ">=" instead.... Read more

    Affected Products : linux_kernel
    • Published: Jul. 27, 2019
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2016-10763

    The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.... Read more

    Affected Products : camptix_event_ticketing
    • Published: Jul. 18, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-10762

    The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.... Read more

    Affected Products : camptix_event_ticketing
    • Published: Jul. 18, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10761

    Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.... Read more

    • Published: Jun. 29, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-10760

    On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.... Read more

    • Published: Jun. 11, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10759

    The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks .php uploads.... Read more

    Affected Products : precurio
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10758

    PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.... Read more

    Affected Products : phpkit
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10757

    In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.... Read more

    Affected Products : readaxo
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10756

    Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.... Read more

    Affected Products : kliqqi_cms
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10755

    AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.... Read more

    Affected Products : abantecart
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10754

    modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.... Read more

    Affected Products : vtiger_crm
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10753

    e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.... Read more

    Affected Products : e107
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10752

    serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.... Read more

    Affected Products : serendipity
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2016-10751

    osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=a... Read more

    Affected Products : osclass
    • Published: May. 24, 2019
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2016-10750

    In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the at... Read more

    Affected Products : hazelcast
    • Published: May. 22, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-10746

    libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.... Read more

    Affected Products : debian_linux libvirt
    • Published: Apr. 18, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292836 Results