Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-10-06 CVE-2016-1000217 SQL Injection vulnerability in Zotpress Project Zotpress 6.1.2
Zotpress plugin for WordPress SQLi in zp_get_account()
network
low complexity
zotpress-project CWE-89
critical
9.8
2016-10-06 CVE-2016-1000125 SQL Injection vulnerability in Huge-It Catalog 1.0.7
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
network
low complexity
huge-it CWE-89
critical
9.8
2016-10-06 CVE-2016-1000124 SQL Injection vulnerability in Huge-It Portfolio Gallery 1.0.6
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
network
low complexity
huge-it CWE-89
critical
9.8
2016-10-06 CVE-2016-1000123 SQL Injection vulnerability in Huge-It Video Gallery 1.0.9
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
network
low complexity
huge-it CWE-89
critical
9.8
2016-10-06 CVE-2016-1000114 Cross-site Scripting vulnerability in Huge-It Gallery 1.1.5
XSS in huge IT gallery v1.1.5 for Joomla
network
low complexity
huge-it CWE-79
6.1
2016-10-06 CVE-2016-1000113 SQL Injection vulnerability in Huge-It Gallery 1.1.5
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
network
low complexity
huge-it CWE-89
critical
9.8
2016-10-06 CVE-2016-1000112 Path Traversal vulnerability in Contussupport Contus-Video-Comments 1.0
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
network
low complexity
contussupport CWE-22
critical
9.1
2016-10-06 CVE-2016-1000009 7PK - Security Features vulnerability in Tp-Link
TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net.
network
low complexity
tp-link CWE-254
7.5
2016-10-06 CVE-2016-1000000 SQL Injection vulnerability in Progress Whatsup Gold
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
network
low complexity
progress CWE-89
8.8
2016-10-06 CVE-2015-1000013 Unrestricted Upload of File with Dangerous Type vulnerability in Csv2Wpec-Coupon Project Csv2Wpec-Coupon 1.1
Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1
local
low complexity
csv2wpec-coupon-project CWE-434
7.8