Latest CVE Feed
-
9.8
CRITICALCVE-2017-5611
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type nam... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-5610
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10186
An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10185
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10184
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10183
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10182
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10181
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10180
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10179
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10178
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10177
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10176
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10175
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulne... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10174
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.... Read more
Affected Products : d7000_firmware r6220_firmware d7800_firmware r7500_firmware r7500v2_firmware wnr2000v5_firmware wnr2020_firmware d6100_firmware jnr1010v2_firmware jwnr2010v5_firmware +46 more products- Actively Exploited
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5609
SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.... Read more
Affected Products : serendipity- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5608
Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename.... Read more
Affected Products : piwigo- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-9554
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticT... Read more
Affected Products : web_appliance- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-9553
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for bl... Read more
Affected Products : web_appliance- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5486
The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().... Read more
Affected Products : tcpdump- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025