8.5

CVSS4.0

CVE-2016-20058 - Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or systeโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:51 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

8.5

CVSS4.0

CVE-2016-20057 - NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart orโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:51 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

8.5

CVSS4.0

CVE-2016-20056 - Spy Emergency build 23.0.205 Unquoted Service Path Privilege Escalation

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:50 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

8.5

CVSS4.0

CVE-2016-20055 - IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when the service restarts oโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:50 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

6.9

CVSS4.0

CVE-2016-20053 - Redaxo CMS 5.2 Cross-Site Request Forgery via users endpoint

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the users endpoint with hidden fields contโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:50 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

9.3

CVSS4.0

CVE-2016-20052 - Snews CMS 1.7 Unrestricted File Upload via snews_files

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accesโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:50 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

6.9

CVSS4.0

CVE-2016-20051 - Snews CMS 1.7 Cross-Site Request Forgery via changeup

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requeโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:50 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

6.9

CVSS4.0

CVE-2016-20050 - NetSchedScan 1.0 Buffer Overflow Denial of Service

NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a crafted payload containing 388 bytes of data followed by 4 bytes of EIP overwrite into the Hostnโ€ฆ

๐Ÿ“… Published: April 4, 2026, 1:50 p.m. ๐Ÿ”„ Last Modified: April 4, 2026, 2:16 p.m.

8.8

CVSS3.1

CVE-2026-3666 - wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and abovโ€ฆ

๐Ÿ“… Published: April 4, 2026, 11:16 a.m. ๐Ÿ”„ Last Modified: April 4, 2026, 11:16 a.m.

7.2

CVSS3.1

CVE-2026-2936 - Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injโ€ฆ

๐Ÿ“… Published: April 4, 2026, 11:16 a.m. ๐Ÿ”„ Last Modified: April 4, 2026, 11:16 a.m.
Total resulsts: 342251
Page 3 of 34,226
ยซ previous page ยป next page
Filters