Latest CVE Feed
-
5.4
MEDIUMCVE-2015-4457
Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.... Read more
Affected Products : cloudera_manager- EPSS Score: %0.19
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4412
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.... Read more
Affected Products : bson- EPSS Score: %1.75
- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-4411
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-... Read more
- EPSS Score: %3.08
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-4410
The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted ... Read more
- EPSS Score: %2.28
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2015-4400
Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless network configuration by pressing the set up button and leveraging an API in the GainSpan Wi-Fi module.... Read more
- EPSS Score: %0.15
- Published: Feb. 06, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-4179
Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier for Wordpress.... Read more
Affected Products : codestyling_localization- EPSS Score: %0.17
- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-4117
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.... Read more
Affected Products : control_panel- EPSS Score: %7.86
- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4043
SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands via the ctl00$cphMainContent$txtUserName parameter to frmLogin.aspx.... Read more
Affected Products : esp_hr_management- EPSS Score: %0.44
- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4042
Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.... Read more
Affected Products : coreutils- EPSS Score: %0.39
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-4041
The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-... Read more
Affected Products : coreutils- EPSS Score: %0.07
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-4039
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can... Read more
Affected Products : wp_membership- EPSS Score: %0.30
- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2015-3965
Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly exposed function.... Read more
- EPSS Score: %0.44
- Published: Mar. 23, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-3956
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unauthorized configuration changes from... Read more
- EPSS Score: %0.24
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-3954
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could... Read more
- EPSS Score: %0.54
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-3953
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and ... Read more
- EPSS Score: %0.25
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3952
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and ... Read more
- EPSS Score: %0.12
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-3907
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.... Read more
Affected Products : codeigniter-restserver- EPSS Score: %0.46
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-3898
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/log... Read more
Affected Products : bonita_bpm_portal- EPSS Score: %2.23
- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3888
Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.... Read more
Affected Products : sailfish_os- EPSS Score: %0.24
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3641
bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.... Read more
Affected Products : bitcoin_core- EPSS Score: %0.83
- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024