|
265851
|
4.9 |
MEDIUM
Network
|
atlassian
|
crowd
|
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to reques…
|
CWE-200
Information Exposure
|
CVE-2016-10740
|
2024-11-21 11:44 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265852
|
5.3 |
MEDIUM
Local
|
gnu opensuse
|
glibc leap
|
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, whic…
|
CWE-20
Improper Input Validation
|
CVE-2016-10739
|
2024-11-21 11:44 |
2019-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265853
|
8.8 |
HIGH
Network
|
castlamp
|
zenbership
|
Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
|
CWE-352
Origin Validation Error
|
CVE-2016-10738
|
2024-11-21 11:44 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265854
|
5.4 |
MEDIUM
Network
|
s9y
|
serendipity
|
Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10737
|
2024-11-21 11:44 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265855
|
6.1 |
MEDIUM
Network
|
devpups
|
social_pug
|
The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10736
|
2024-11-21 11:44 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265856
|
6.1 |
MEDIUM
Network
|
getbootstrap
|
bootstrap
|
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10735
|
2024-11-21 11:44 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265857
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_835_firmware sda660_firmware
|
While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identity in Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM965…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-10502
|
2024-11-21 11:44 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265858
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
|
CWE-285
Improper Authorization
|
CVE-2016-10734
|
2024-11-21 11:44 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265859
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
|
CWE-22
Path Traversal
|
CVE-2016-10733
|
2024-11-21 11:44 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265860
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to user…
|
CWE-287
Improper Authentication
|
CVE-2016-10732
|
2024-11-21 11:44 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|