Search Results (324445 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-10873 1 Wpseeds 1 Wp Database Backup 2024-11-21 6.1 Medium
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
CVE-2016-10872 1 Ultimatemember 1 Ultimate Member 2024-11-21 6.1 Medium
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
CVE-2016-10871 1 Ibericode 1 Mailchimp 2024-11-21 N/A
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
CVE-2016-10870 1 Gtranslate 1 Google Language Translator 2024-11-21 N/A
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
CVE-2016-10869 1 Bestwebsoft 1 Contact Form 2024-11-21 N/A
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
CVE-2016-10868 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 N/A
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
CVE-2016-10867 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 6.1 Medium
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
CVE-2016-10866 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 N/A
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
CVE-2016-10865 1 23systems 1 Lightbox Plus Colorbox 2024-11-21 N/A
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
CVE-2016-10864 1 Netgear 2 Ex7000, Ex7000 Firmware 2024-11-21 N/A
NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID.
CVE-2016-10863 1 Edimax 4 7237rpd, 7237rpd Firmware, Ew-7438rpn Mini and 1 more 2024-11-21 N/A
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
CVE-2016-10862 1 Neetcables 2 Airstream Nas, Airstream Nas Firmware 2024-11-21 N/A
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
CVE-2016-10861 1 Neetcables 2 Airstream, Airstream Nas Firmware 2024-11-21 N/A
Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.
CVE-2016-10860 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
CVE-2016-10859 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
CVE-2016-10858 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
CVE-2016-10857 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
CVE-2016-10856 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
CVE-2016-10855 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
CVE-2016-10854 1 Cpanel 1 Cpanel 2024-11-21 N/A
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).