|
273791
|
8.8 |
HIGH
Network
|
elfden
|
eshop_plugin
|
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote…
|
CWE-89
SQL Injection
|
CVE-2016-0769
|
2024-11-21 11:42 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273792
|
6.1 |
MEDIUM
Network
|
elfden
|
eshop_plugin
|
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2016-0765
|
2024-11-21 11:42 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273793
|
9.8 |
CRITICAL
Network
|
mailcwp_project
|
mailcwp
|
Mailcwp remote file upload vulnerability incomplete fix v1.100
|
CWE-77 CWE-284
Command Injection Improper Access Control
|
CVE-2016-1000156
|
2024-11-21 11:42 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273794
|
8.4 |
HIGH
Local
|
emc
|
avamar_data_store avamar_server_virtual_edition
|
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may expose the Avamar servers to potentially be compromised by malicious users.
|
CWE-20
Improper Input Validation
|
CVE-2016-0909
|
2024-11-21 11:42 |
2016-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273795
|
7.2 |
HIGH
Network
|
huge-it
|
slider
|
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
|
CWE-89
SQL Injection
|
CVE-2016-1000122
|
2024-11-21 11:42 |
2016-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273796
|
4.8 |
MEDIUM
Network
|
huge-it
|
slider
|
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000121
|
2024-11-21 11:42 |
2016-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273797
|
7.2 |
HIGH
Network
|
huge-it
|
catalog
|
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
|
CWE-89
SQL Injection
|
CVE-2016-1000120
|
2024-11-21 11:42 |
2016-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273798
|
8.8 |
HIGH
Network
|
ruckus
|
wireless_h500
|
Ruckus Wireless H500 web management interface CSRF
|
CWE-352
Origin Validation Error
|
CVE-2016-1000213
|
2024-11-21 11:42 |
2016-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273799
|
3.7 |
LOW
Network
|
gnome redhat
|
shotwell enterprise_linux
|
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1000033
|
2024-11-21 11:42 |
2016-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273800
|
7.5 |
HIGH
Network
|
python
|
tgcaptcha2
|
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.
|
CWE-284
Improper Access Control
|
CVE-2016-1000032
|
2024-11-21 11:42 |
2016-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|