Vulnerabilities (CVE)

Total 398379 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1000124 1 Huge-it 1 Portfolio Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVE-2016-1000123 1 Huge-it 1 Video Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CVE-2016-1000122 1 Huge-it 1 Slider 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000121 1 Huge-it 1 Slider 2026-06-17 3.5 LOW 4.8 MEDIUM
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000120 1 Huge-it 1 Catalog 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000119 1 Huge-it 1 Catalog 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000118 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000117 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000116 1 Huge-it 1 Portfolio Gallery Manager 2026-06-17 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000115 1 Huge-it 1 Portfolio Gallery Manager 2026-06-17 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000114 1 Huge-it 1 Gallery 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS in huge IT gallery v1.1.5 for Joomla
CVE-2016-1000113 1 Huge-it 1 Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
CVE-2016-1000112 1 Contussupport 1 Contus-video-comments 2026-06-17 9.4 HIGH 9.1 CRITICAL
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
CVE-2016-1000111 1 Twisted 1 Twisted 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVE-2016-1000110 3 Debian, Fedoraproject, Python 3 Debian Linux, Fedora, Python 2026-06-17 5.8 MEDIUM 6.1 MEDIUM
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
CVE-2016-1000109 1 Facebook 1 Hhvm 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. This issue affects HHVM versions prior to 3.9.6, all versions between 3.10.0 and 3.12.4 (inclusive), and all versions between 3.13.0 and 3.14.2 (inclusive).
CVE-2016-1000108 2 Debian, Yaws 2 Debian Linux, Yaws 2026-06-17 5.8 MEDIUM 6.1 MEDIUM
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVE-2016-1000107 1 Erlang 1 Erlang\/otp 2026-06-17 5.8 MEDIUM 6.1 MEDIUM
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVE-2016-1000104 2 Apache, Opensuse 3 Mod Fcgid, Leap, Opensuse 2026-06-17 6.5 MEDIUM 8.8 HIGH
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
CVE-2016-1000037 2 Fedoraproject, Redhat 3 Fedora, Enterprise Linux, Pagure 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Pagure: XSS possible in file attachment endpoint