CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2015-1000000

    Last Modified: 12 Apr 2025

    Remote file upload vulnerability in mailcwp v1.99 wordpress plugin

    Published: 6 Oct 2016
    8.2
    High

    CVE-2015-1000002

    Last Modified: 12 Apr 2025

    Open Proxy in filedownload v1.4 wordpress plugin

    Published: 6 Oct 2016
    7.5
    High

    CVE-2015-1000007

    Last Modified: 12 Apr 2025

    Remote file download vulnerability in wptf-image-gallery v1.03

    Published: 6 Oct 2016
    5.3
    Medium

    CVE-2015-1000008

    Last Modified: 12 Apr 2025

    Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2

    Published: 6 Oct 2016
    9.1
    Critical

    CVE-2015-1000009

    Last Modified: 12 Apr 2025

    Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05

    Published: 6 Oct 2016
    7.5
    High

    CVE-2015-1000010

    Last Modified: 12 Apr 2025

    Remote file download in simple-image-manipulator v1.0 wordpress plugin

    Published: 6 Oct 2016
    9.8
    Critical

    CVE-2015-1000011

    Last Modified: 12 Apr 2025

    Blind SQL Injection in wordpress plugin dukapress v2.5.9

    Published: 6 Oct 2016
    7.5
    High

    CVE-2015-1000012

    Last Modified: 12 Apr 2025

    Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin

    Published: 6 Oct 2016
    7.8
    High

    CVE-2015-1000013

    Last Modified: 12 Apr 2025

    Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1

    Published: 6 Oct 2016
    Unknown

    CVE-2016-1000102

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5387. Reason: This candidate is a duplicate of CVE-2016-5387. Notes: All CVE users should reference CVE-2016-5387 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Oct 2016
    9.8
    Critical

    CVE-2016-1000123

    Last Modified: 12 Apr 2025

    Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla

    Published: 6 Oct 2016
    Unknown

    CVE-2016-1000101

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5386. Reason: This candidate is a duplicate of CVE-2016-5386. Notes: All CVE users should reference CVE-2016-5386 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Oct 2016
    Unknown

    CVE-2016-1000014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3956. Reason: This candidate is a duplicate of CVE-2016-3956. Notes: All CVE users should reference CVE-2016-3956 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Oct 2016
    Unknown

    CVE-2016-1000100

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5385. Reason: This candidate is a duplicate of CVE-2016-5385. Notes: All CVE users should reference CVE-2016-5385 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Oct 2016
    9.8
    Critical

    CVE-2016-1000113

    Last Modified: 12 Apr 2025

    XSS and SQLi in huge IT gallery v1.1.5 for Joomla

    Published: 6 Oct 2016
    6.1
    Medium

    CVE-2016-1000114

    Last Modified: 12 Apr 2025

    XSS in huge IT gallery v1.1.5 for Joomla

    Published: 6 Oct 2016
    9.8
    Critical

    CVE-2016-1000217

    Last Modified: 12 Apr 2025

    Zotpress plugin for WordPress SQLi in zp_get_account()

    Published: 6 Oct 2016
    9.8
    Critical

    CVE-2016-1453

    Last Modified: 12 Apr 2025

    Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long parameters in a packet header, aka Bug ID CSCuy95701.

    Published: 6 Oct 2016
    6.5
    Medium

    CVE-2016-1454

    Last Modified: 12 Apr 2025

    Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.

    Published: 6 Oct 2016
    6.1
    Medium

    CVE-2016-6027

    Last Modified: 12 Apr 2025

    The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.

    Published: 6 Oct 2016
    7.8
    High

    CVE-2016-6428

    Last Modified: 12 Apr 2025

    Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.

    Published: 6 Oct 2016
    6.5
    Medium

    CVE-2016-6435

    Last Modified: 12 Apr 2025

    The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.

    Published: 6 Oct 2016
    6.1
    Medium

    CVE-2016-6436

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in HostScan Engine 3.0.08062 through 3.1.14018 in the Cisco Host Scan package, as used in ASA Web VPN, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz14682.

    Published: 6 Oct 2016
    7.5
    High

    CVE-2016-6422

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles certain operators, flags, and keywords in TCAM share ACLs, which allows remote attackers to bypass intended access restrictions by sending packets that should have been recognized by a filter, aka Bug ID CSCuy64806.

    Published: 6 Oct 2016
    6.1
    Medium

    CVE-2016-6425

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.

    Published: 6 Oct 2016
    7.5
    High

    CVE-2016-6023

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to read arbitrary files via a crafted URL.

    Published: 6 Oct 2016
    8
    High

    CVE-2015-0721

    Last Modified: 12 Apr 2025

    Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via crafted parameters in an SSH connection negotiation, aka Bug IDs CSCum35502, CSCuw78669, CSCuw79754, and CSCux88492.

    Published: 6 Oct 2016
    7.5
    High

    CVE-2015-6393

    Last Modified: 12 Apr 2025

    Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via malformed IPv4 DHCP packets to the DHCPv4 relay agent, aka Bug IDs CSCuq39250, CSCus21733, CSCus21739, CSCut76171, and CSCux67182.

    Published: 6 Oct 2016
    5.9
    Medium

    CVE-2016-6025

    Last Modified: 12 Apr 2025

    The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involving a modified URL.

    Published: 6 Oct 2016
    5.3
    Medium

    CVE-2016-6026

    Last Modified: 12 Apr 2025

    The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.

    Published: 6 Oct 2016
    6.5
    Medium

    CVE-2016-6424

    Last Modified: 12 Apr 2025

    The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942.

    Published: 6 Oct 2016
    8.8
    High

    CVE-2016-6427

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.

    Published: 6 Oct 2016
    8.8
    High

    CVE-2016-6433

    Last Modified: 12 Apr 2025

    The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.

    Published: 6 Oct 2016
    7.8
    High

    CVE-2016-6434

    Last Modified: 12 Apr 2025

    Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.

    Published: 6 Oct 2016
    7.5
    High

    CVE-2016-6653

    Last Modified: 12 Apr 2025

    The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information by reading syslog messages, as demonstrated by cleartext credentials.

    Published: 6 Oct 2016
    7.5
    High

    CVE-2015-6392

    Last Modified: 12 Apr 2025

    Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSCur93159, CSCus21693, and CSCut76171.

    Published: 6 Oct 2016
    5.5
    Medium

    CVE-2016-8681

    Last Modified: 20 Apr 2025

    The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.

    Published: 6 Oct 2016
    9.8
    Critical

    CVE-2016-6808

    Last Modified: 20 Apr 2025

    Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

    Published: 6 Oct 2016
    6
    Medium

    CVE-2016-8576

    Last Modified: 12 Apr 2025

    The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.

    Published: 6 Oct 2016
    5.5
    Medium

    CVE-2016-9318

    Last Modified: 4 Dec 2025

    libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

    Published: 6 Oct 2016
    6.5
    Medium

    CVE-2018-18065

    Last Modified: 21 Nov 2024

    _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

    Published: 6 Oct 2016
    9.8
    Critical

    CVE-2016-7480

    Last Modified: 20 Apr 2025

    The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

    Published: 6 Oct 2016
    6.5
    Medium

    CVE-2016-8679

    Last Modified: 20 Apr 2025

    The _dwarf_get_size_of_val function in libdwarf/dwarf_util.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.

    Published: 6 Oct 2016
    7.5
    High

    CVE-2016-6426

    Last Modified: 12 Apr 2025

    The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6385

    Last Modified: 12 Apr 2025

    Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.

    Published: 5 Oct 2016
    5.3
    Medium

    CVE-2016-6421

    Last Modified: 12 Apr 2025

    Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID CSCvb05643.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-1455

    Last Modified: 12 Apr 2025

    Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CSCuz05365.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6393

    Last Modified: 12 Apr 2025

    The AAA service in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.1 through 3.18 and 16.2 allows remote attackers to cause a denial of service (device reload) via a failed SSH connection attempt that is mishandled during generation of an error-log message, aka Bug ID CSCuy87667.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6379

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089.

    Published: 5 Oct 2016
    8.1
    High

    CVE-2016-6380

    Last Modified: 12 Apr 2025

    The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.

    Published: 5 Oct 2016