|
266361
|
8.8 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
|
CWE-20
Improper Input Validation
|
CVE-2016-10850
|
2024-11-21 11:44 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266362
|
8.8 |
HIGH
Network
|
edx
|
edx-platform
|
edx-platform before 2016-06-06 allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2016-10766
|
2024-11-21 11:44 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266363
|
5.3 |
MEDIUM
Network
|
edx
|
edx-platform
|
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
|
CWE-20
Improper Input Validation
|
CVE-2016-10765
|
2024-11-21 11:44 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266364
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10764
|
2024-11-21 11:44 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266365
|
4.8 |
MEDIUM
Network
|
automattic
|
camptix_event_ticketing
|
The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10763
|
2024-11-21 11:44 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266366
|
7.5 |
HIGH
Network
|
automattic
|
camptix_event_ticketing
|
The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.
|
CWE-77
Command Injection
|
CVE-2016-10762
|
2024-11-21 11:44 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266367
|
6.5 |
MEDIUM
Adjacent
|
logitech
|
k400r_firmware k360_firmware k750_firmware k830_firmware unifying_receiver_firmware
|
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
|
CWE-74
Injection
|
CVE-2016-10761
|
2024-11-21 11:44 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266368
|
9.8 |
CRITICAL
Network
|
seowonintech
|
swr-300a_firmware swr-300b_firmware swr-300c_firmware swr-300bg_firmware
|
On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.
|
CWE-77
Command Injection
|
CVE-2016-10760
|
2024-11-21 11:44 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266369
|
9.8 |
CRITICAL
Network
|
precurio
|
precurio
|
The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used t…
|
CWE-22
Path Traversal
|
CVE-2016-10759
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266370
|
8.8 |
HIGH
Network
|
phpkit
|
phpkit
|
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10758
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|