CVE-2019-16277
PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.
Source: CVE-2019-16277
CVE-2019-16277
PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.
Source: CVE-2019-16277
CVE-2017-18615
The kama-clic-counter plugin before 3.5.0 for WordPress has XSS.
Source: CVE-2017-18615
CVE-2016-10943
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
Source: CVE-2016-10943
CVE-2017-18613
The trust-form plugin 2.0 for WordPress has XSS via the wp-admin/admin.php?page=trust-form-edit page parameter.
Source: CVE-2017-18613
CVE-2017-18614
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
Source: CVE-2017-18614
CVE-2016-10940
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Source: CVE-2016-10940
CVE-2016-10942
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.
Source: CVE-2016-10942
CVE-2016-10941
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.
Source: CVE-2016-10941
CVE-2016-10938
The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
Source: CVE-2016-10938
CVE-2016-10939
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
Source: CVE-2016-10939