Latest CVE Feed
-
8.8
HIGHCVE-2015-7339
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.... Read more
Affected Products : jce- EPSS Score: %0.42
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2015-7338
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.... Read more
Affected Products : acymailing- EPSS Score: %0.27
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-7336
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update t... Read more
Affected Products : system_update- EPSS Score: %0.11
- Published: Mar. 27, 2020
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2015-7335
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code ... Read more
Affected Products : system_update- EPSS Score: %0.04
- Published: Mar. 27, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7334
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe ... Read more
Affected Products : system_update- EPSS Score: %0.04
- Published: Mar. 27, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7333
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe ... Read more
Affected Products : system_update- EPSS Score: %0.04
- Published: Mar. 27, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUM- EPSS Score: %0.31
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-7266
The Interactive Advertising Bureau (IAB) OpenRTB 2.3 protocol implementation might allow remote attackers to conceal the status of ad transactions and potentially compromise bid integrity by leveraging failure to limit the time between bid responses and i... Read more
Affected Products : open_real-time_bidding- EPSS Score: %0.27
- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-6970
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.... Read more
- EPSS Score: %9.42
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2015-6964
MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for themselves.) This occ... Read more
Affected Products : multibit_hd- EPSS Score: %0.07
- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-6960
edx-platform before 2015-09-17 allows XSS via a team name.... Read more
Affected Products : edx-platform- EPSS Score: %0.36
- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-6926
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token.... Read more
Affected Products : eshop- EPSS Score: %0.27
- Published: Jan. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-6922
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative ... Read more
Affected Products : virtual_system_administrator- EPSS Score: %76.72
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-6815
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vec... Read more
Affected Products : ubuntu_linux enterprise_linux fedora openstack qemu xen eos suse_linux_enterprise_desktop suse_linux_enterprise_server suse_linux_enterprise_software_development_kit +1 more products- EPSS Score: %1.90
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-6591
Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.... Read more
Affected Products : articlefr- EPSS Score: %0.06
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-6589
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files... Read more
Affected Products : virtual_system_administrator- EPSS Score: %15.62
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-6569
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack.... Read more
Affected Products : floodlight- EPSS Score: %0.51
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-6544
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.... Read more
Affected Products : itop- EPSS Score: %51.08
- Published: Feb. 20, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-6497
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execut... Read more
- EPSS Score: %2.92
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-6495
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.... Read more
Affected Products : cloudera_manager- EPSS Score: %0.40
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024