Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2016-10885

    The wp-editor plugin before 1.2.6 for WordPress has CSRF.... Read more

    Affected Products : wp_editor
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10884

    The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.... Read more

    Affected Products : simple_membership
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-10883

    The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.... Read more

    Affected Products : simple_add_pages_or_posts
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10882

    The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.... Read more

    Affected Products : google_doc_embedder
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10881

    The google-document-embedder plugin before 2.6.2 for WordPress has XSS.... Read more

    Affected Products : google_doc_embedder
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10880

    The google-document-embedder plugin before 2.6.1 for WordPress has XSS.... Read more

    Affected Products : google_doc_embedder
    • Published: Aug. 14, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10879

    The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.... Read more

    Affected Products : live_chat
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10877

    The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.... Read more

    Affected Products : wp_editor wp_editor
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10876

    The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.... Read more

    Affected Products : wp_database_backup
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10875

    The wp-database-backup plugin before 4.3.1 for WordPress has XSS.... Read more

    Affected Products : wp_database_backup
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-10874

    The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.... Read more

    Affected Products : wp_database_backup
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10873

    The wp-database-backup plugin before 4.3.3 for WordPress has XSS.... Read more

    Affected Products : wp_database_backup
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10872

    The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.... Read more

    Affected Products : ultimate_member
    • Published: Aug. 12, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10871

    The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.... Read more

    Affected Products : mailchimp
    • Published: Aug. 13, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10870

    The google-language-translator plugin before 5.0.06 for WordPress has XSS.... Read more

    Affected Products : google_language_translator
    • Published: Aug. 13, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10869

    The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.... Read more

    Affected Products : contact_form
    • Published: Aug. 13, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10868

    The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.... Read more

    • Published: Aug. 13, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10867

    The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.... Read more

    • Published: Aug. 13, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10866

    The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.... Read more

    • Published: Aug. 13, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-10865

    The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.... Read more

    Affected Products : lightbox_plus_colorbox
    • Published: Aug. 09, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 293288 Results