Latest CVE Feed
-
7.4
HIGHCVE-2015-5039
The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof se... Read more
Affected Products : rational_clearcase- Published: Mar. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5016
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access ... Read more
- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-4987
The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors. IBM X-Force ID: 105896.... Read more
Affected Products : tealeaf_customer_experience- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-4954
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors. IBM X-Force ID: 105200.... Read more
Affected Products : bigfix_remote_control- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2015-4953
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.... Read more
Affected Products : bigfix_remote_control- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-4952
The on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. IBM X-Force ID: 105196.... Read more
Affected Products : endpoint_manager_for_remote_control- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4719
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.... Read more
Affected Products : pexip_infinity- Published: Sep. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4664
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.... Read more
- Published: Jun. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4633
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in t... Read more
Affected Products : koha- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-4632
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path para... Read more
Affected Products : koha- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-searc... Read more
Affected Products : koha- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2015-4630
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that cr... Read more
Affected Products : koha- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-4617
Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.... Read more
Affected Products : easy2map-photos- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4615
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables... Read more
Affected Products : easy2map-photos- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-4557
Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirec... Read more
Affected Products : nextend_twitter_connect- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-4553
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.... Read more
Affected Products : dedecms- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-4461
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.... Read more
Affected Products : efront- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-4457
Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.... Read more
Affected Products : cloudera_manager- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4412
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.... Read more
Affected Products : bson- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-4411
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-... Read more
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024