Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2015-4617

    Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.... Read more

    Affected Products : easy2map-photos
    • Published: Feb. 15, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2015-4615

    Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables... Read more

    Affected Products : easy2map-photos
    • Published: Feb. 15, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2015-4557

    Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirec... Read more

    Affected Products : nextend_twitter_connect
    • Published: Apr. 12, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2015-4553

    A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.... Read more

    Affected Products : dedecms
    • Published: Jan. 06, 2020
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2015-4461

    Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.... Read more

    Affected Products : efront
    • Published: Feb. 05, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2015-4457

    Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.... Read more

    Affected Products : cloudera_manager
    • Published: Nov. 26, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2015-4412

    BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.... Read more

    Affected Products : bson
    • Published: Feb. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2015-4411

    The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-... Read more

    Affected Products : fedora bson
    • Published: Feb. 20, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2015-4410

    The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted ... Read more

    Affected Products : fedora moped
    • Published: Feb. 20, 2020
    • Modified: Nov. 21, 2024
  • 4.6

    MEDIUM
    CVE-2015-4400

    Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless network configuration by pressing the set up button and leveraging an API in the GainSpan Wi-Fi module.... Read more

    Affected Products : ring_firmware ring
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2015-4179

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier for Wordpress.... Read more

    Affected Products : codestyling_localization
    • Published: Feb. 05, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2015-4117

    Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.... Read more

    Affected Products : control_panel
    • Published: Feb. 28, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2015-4043

    SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands via the ctl00$cphMainContent$txtUserName parameter to frmLogin.aspx.... Read more

    Affected Products : esp_hr_management
    • Published: Jun. 19, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2015-4042

    Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.... Read more

    Affected Products : coreutils
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2015-4041

    The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-... Read more

    Affected Products : coreutils
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2015-4039

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can... Read more

    Affected Products : wp_membership
    • Published: Jan. 06, 2020
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2015-3965

    Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly exposed function.... Read more

    • Published: Mar. 23, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2015-3956

    Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unauthorized configuration changes from... Read more

    • Published: Mar. 25, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2015-3954

    Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could... Read more

    • Published: Mar. 25, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2015-3953

    Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and ... Read more

    • Published: Mar. 25, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292811 Results