Latest CVE Feed
-
10.0
HIGHCVE-2015-3956
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unauthorized configuration changes from... Read more
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-3954
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could... Read more
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-3953
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and ... Read more
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3952
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and ... Read more
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-3907
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.... Read more
Affected Products : codeigniter-restserver- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-3898
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/log... Read more
Affected Products : bonita_bpm_portal- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3888
Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.... Read more
Affected Products : sailfish_os- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3641
bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.... Read more
Affected Products : bitcoin_core- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-3619
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_na... Read more
Affected Products : virtuemart- Published: Feb. 06, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-3618
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.... Read more
Affected Products : business_process_intelligence- Published: Feb. 06, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-3613
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page... Read more
Affected Products : fortimanager- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-3612
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.... Read more
Affected Products : fortimanager- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2015-3611
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.... Read more
Affected Products : fortimanager- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-3425
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.... Read more
Affected Products : content_resource_management_system- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-3424
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.... Read more
Affected Products : content_resource_management_system- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-3423
Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3,... Read more
Affected Products : resource_management_system- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3406
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.... Read more
- Published: Nov. 29, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-3309
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE:... Read more
Affected Products : etherpad- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-3298
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.... Read more
Affected Products : ykneo-openpgp- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2015-3207
In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.... Read more
Affected Products : origin- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024