|
268661
|
9.8 |
CRITICAL
Network
|
huge-it
|
image_gallery
|
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gal…
|
CWE-89
SQL Injection
|
CVE-2016-11018
|
2024-11-21 11:45 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268662
|
9.8 |
CRITICAL
Network
|
akips
|
network_monitor
|
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a …
|
CWE-78
OS Command
|
CVE-2016-11017
|
2024-11-21 11:45 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268663
|
6.1 |
MEDIUM
Network
|
netgear
|
jnr1010_firmware
|
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11016
|
2024-11-21 11:45 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268664
|
6.5 |
MEDIUM
Network
|
netgear
|
jnr1010_firmware
|
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
|
CWE-352
Origin Validation Error
|
CVE-2016-11015
|
2024-11-21 11:45 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268665
|
9.8 |
CRITICAL
Network
|
netgear
|
jnr1010_firmware
|
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
|
CWE-613
Insufficient Session Expiration
|
CVE-2016-11014
|
2024-11-21 11:45 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268666
|
6.1 |
MEDIUM
Network
|
agentevolution
|
impress_listings
|
The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11013
|
2024-11-21 11:45 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268667
|
5.4 |
MEDIUM
Network
|
solaplugins
|
sola_support_tickets
|
The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11012
|
2024-11-21 11:45 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268668
|
6.5 |
MEDIUM
Network
|
usabilitydynamics
|
wp-invoice
|
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
|
CWE-269
Improper Privilege Management
|
CVE-2016-11011
|
2024-11-21 11:45 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268669
|
5.3 |
MEDIUM
Network
|
usabilitydynamics
|
wp-invoice
|
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2016-11010
|
2024-11-21 11:45 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268670
|
5.3 |
MEDIUM
Network
|
usabilitydynamics
|
wp-invoice
|
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2016-11009
|
2024-11-21 11:45 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|