|
266331
|
8.8 |
HIGH
Network
|
add_from_server_project
|
add_from_server
|
The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
|
CWE-352
Origin Validation Error
|
CVE-2016-10914
|
2024-11-21 11:45 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266332
|
6.1 |
MEDIUM
Network
|
joomunited
|
wp_latest_posts
|
The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10913
|
2024-11-21 11:45 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266333
|
6.1 |
MEDIUM
Network
|
crayon_syntax_highlighter_project
|
crayon_syntax_highlighter
|
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10893
|
2024-11-21 11:45 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266334
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in the function ad5755_parse_dt.
|
CWE-787
Out-of-bounds Write
|
CVE-2016-10907
|
2024-11-21 11:45 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266335
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a race condition between the functions arc_emac_tx and arc_emac_tx_clean.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2016-10906
|
2024-11-21 11:45 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266336
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
|
CWE-416
Use After Free
|
CVE-2016-10905
|
2024-11-21 11:45 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266337
|
9.8 |
CRITICAL
Network
|
olimometer_project
|
olimometer
|
The olimometer plugin before 2.57 for WordPress has SQL injection.
|
CWE-89
SQL Injection
|
CVE-2016-10904
|
2024-11-21 11:45 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266338
|
4.6 |
MEDIUM
Physics
|
xtrlock_project debian
|
xtrlock debian_linux
|
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrol…
|
CWE-254
7PK - Security Features
|
CVE-2016-10894
|
2024-11-21 11:45 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266339
|
5.9 |
MEDIUM
Network
|
jetstar
|
jetstar
|
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certific…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1221
|
2024-11-21 11:45 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266340
|
5.9 |
MEDIUM
Network
|
the_hyakugo_bank
|
105_bank
|
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informatio…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1210
|
2024-11-21 11:45 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|