Vulnerabilities (CVE)

Total 299226 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10946 1 Wp-d3 Project 1 Wp-d3 2024-11-21 6.8 MEDIUM 8.8 HIGH
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
CVE-2016-10945 1 Pagelines 1 Pagelines 2024-11-21 6.8 MEDIUM 8.8 HIGH
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
CVE-2016-10944 1 Wpmaz 1 Multisite Post Duplicator 2024-11-21 6.8 MEDIUM 8.8 HIGH
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
CVE-2016-10943 1 Zx-csv-upload Project 1 Zx-csv-upload 2024-11-21 6.5 MEDIUM 7.2 HIGH
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
CVE-2016-10942 1 Podlove 1 Podlove Podcast Publisher 2024-11-21 7.5 HIGH 9.8 CRITICAL
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.
CVE-2016-10941 1 Podlove 1 Podlove Podcast Publisher 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.
CVE-2016-10940 1 Zm-gallery Project 1 Zm-gallery 2024-11-21 6.5 MEDIUM 7.2 HIGH
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
CVE-2016-10939 1 Xtremelocator 1 Xtremelocator 2024-11-21 6.5 MEDIUM 7.2 HIGH
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
CVE-2016-10938 1 Copy-me Project 1 Copy-me 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
CVE-2016-10937 1 Imapfilter Project 1 Imapfilter 2024-11-21 5.0 MEDIUM 7.5 HIGH
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
CVE-2016-10936 1 Wp-polls Project 1 Wp-polls 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
CVE-2016-10935 1 Visser 1 Store Exporter For Woocommerce 2024-11-21 7.5 HIGH 9.8 CRITICAL
The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.
CVE-2016-10934 1 Check Email Project 1 Check Email 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The check-email plugin before 0.5.2 for WordPress has XSS.
CVE-2016-10933 1 Portaudio Project 1 Portaudio 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the source code is downloaded over cleartext HTTP.
CVE-2016-10932 2 Hyper, Microsoft 2 Hyper, Windows 2024-11-21 5.8 MEDIUM 4.8 MEDIUM
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.
CVE-2016-10931 1 Rust-openssl Project 1 Rust-openssl 2024-11-21 6.8 MEDIUM 8.1 HIGH
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.
CVE-2016-10930 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2024-11-21 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
CVE-2016-10929 1 Advanced Ajax Page Loader Project 1 Advanced Ajax Page Loader 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.
CVE-2016-10928 1 Onelogin 1 Onelogin Saml Sso 2024-11-21 5.0 MEDIUM 7.5 HIGH
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
CVE-2016-10927 1 Neliosoftware 1 Nelio Ab Testing 2024-11-21 6.4 MEDIUM 10.0 CRITICAL
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.