Latest CVE Feed
-
6.5
MEDIUMCVE-2016-10768
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).... Read more
Affected Products : cpanel- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10767
cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).... Read more
Affected Products : cpanel- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10766
edx-platform before 2016-06-06 allows CSRF.... Read more
Affected Products : edx-platform- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-10765
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.... Read more
Affected Products : edx-platform- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10764
In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so the ">" should be ">=" instead.... Read more
Affected Products : linux_kernel- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2016-10763
The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.... Read more
Affected Products : camptix_event_ticketing- Published: Jul. 18, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-10762
The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.... Read more
Affected Products : camptix_event_ticketing- Published: Jul. 18, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-10761
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.... Read more
Affected Products : k400r_firmware k360_firmware k750_firmware k830_firmware unifying_receiver_firmware k400r k360 k750 k830 unifying_receiver- Published: Jun. 29, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-10760
On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.... Read more
Affected Products : swr-300a_firmware swr-300b_firmware swr-300c_firmware swr-300bg_firmware swr-300a swr-300b swr-300c swr-300bg- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10759
The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks .php uploads.... Read more
Affected Products : precurio- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10758
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.... Read more
Affected Products : phpkit- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10757
In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.... Read more
Affected Products : readaxo- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10756
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.... Read more
Affected Products : kliqqi_cms- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10755
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.... Read more
Affected Products : abantecart- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10754
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.... Read more
Affected Products : vtiger_crm- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10753
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.... Read more
Affected Products : e107- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10752
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.... Read more
Affected Products : serendipity- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2016-10751
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=a... Read more
Affected Products : osclass- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2016-10750
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the at... Read more
Affected Products : hazelcast- Published: May. 22, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-10746
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.... Read more
- Published: Apr. 18, 2019
- Modified: Nov. 21, 2024