Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2015-3956

    Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unauthorized configuration changes from... Read more

    • Published: Mar. 25, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2015-3954

    Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could... Read more

    • Published: Mar. 25, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2015-3953

    Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and ... Read more

    • Published: Mar. 25, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2015-3952

    Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and ... Read more

    • Published: Mar. 25, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2015-3907

    CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.... Read more

    Affected Products : codeigniter-restserver
    • Published: Jul. 03, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2015-3898

    Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/log... Read more

    Affected Products : bonita_bpm_portal
    • Published: Feb. 28, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2015-3888

    Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.... Read more

    Affected Products : sailfish_os
    • Published: Jan. 12, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2015-3641

    bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.... Read more

    Affected Products : bitcoin_core
    • Published: Mar. 12, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2015-3619

    Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_na... Read more

    Affected Products : virtuemart
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2015-3618

    Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.... Read more

    Affected Products : business_process_intelligence
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2015-3613

    A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page... Read more

    Affected Products : fortimanager
    • Published: Feb. 04, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2015-3612

    A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.... Read more

    Affected Products : fortimanager
    • Published: Feb. 04, 2020
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2015-3611

    A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.... Read more

    Affected Products : fortimanager
    • Published: Feb. 04, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2015-3425

    Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.... Read more

    • Published: Dec. 09, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2015-3424

    SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.... Read more

    • Published: Dec. 09, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2015-3423

    Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3,... Read more

    Affected Products : resource_management_system
    • Published: Feb. 08, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2015-3406

    The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.... Read more

    Affected Products : ubuntu_linux module-signature
    • Published: Nov. 29, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2015-3309

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE:... Read more

    Affected Products : etherpad
    • Published: Feb. 13, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2015-3298

    Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.... Read more

    Affected Products : ykneo-openpgp
    • Published: Mar. 30, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2015-3207

    In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.... Read more

    Affected Products : origin
    • Published: Jul. 07, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 292774 Results