Latest CVE Feed
-
8.8
HIGHCVE-2015-10087
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload. Th... Read more
Affected Products : designfolio-plus- EPSS Score: %0.57
- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10086
A vulnerability, which was classified as critical, was found in OpenCycleCompass server-php. Affected is an unknown function of the file api1/login.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remo... Read more
Affected Products : server-php- EPSS Score: %0.04
- Published: Feb. 28, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-10085
A vulnerability was found in GoPistolet. It has been declared as problematic. This vulnerability affects unknown code of the component MTA. The manipulation leads to denial of service. Continious delivery with rolling releases is used by this product. The... Read more
Affected Products : gopistolet- EPSS Score: %0.04
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10084
A vulnerability was found in irontec klear-library chloe and classified as critical. Affected by this issue is the function _prepareWhere of the file Controller/Rest/BaseController.php. The manipulation leads to sql injection. Upgrading to version marla i... Read more
Affected Products : klear-library- EPSS Score: %0.05
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10083
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. Thi... Read more
Affected Products : dynosaur-rails- EPSS Score: %0.06
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10082
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is named c... Read more
Affected Products : libplist- EPSS Score: %0.09
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-10081
A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the file edit_list.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotel... Read more
Affected Products : submitbymailplugin- EPSS Score: %0.05
- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-10080
A vulnerability was found in NREL api-umbrella-web 0.7.1. It has been classified as problematic. This affects an unknown part of the component Admin Data Table Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack ... Read more
Affected Products : api_umbrella- EPSS Score: %0.06
- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-10079
A vulnerability was found in juju2143 WalrusIRC 0.0.2. It has been rated as problematic. This issue affects the function parseLinks of the file public/parser.js. The manipulation of the argument text leads to cross site scripting. The attack may be initia... Read more
Affected Products : walrusirc- EPSS Score: %0.06
- Published: Feb. 13, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-10078
A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross ... Read more
Affected Products : resend_welcome_email- EPSS Score: %0.10
- Published: Feb. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10077
A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affected by this vulnerability is the function index/getPreview of the file code/control/KapostService.php. The manipulation leads to sql in... Read more
Affected Products : silverstripe-kapost-bridge- EPSS Score: %0.04
- Published: Feb. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10076
A vulnerability was found in dimtion Shaarlier up to 1.2.2. It has been declared as critical. Affected by this vulnerability is the function createTag of the file app/src/main/java/com/dimtion/shaarlier/TagsSource.java of the component Tag Handler. The ma... Read more
Affected Products : shaarlier- EPSS Score: %0.04
- Published: Feb. 09, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-10075
A vulnerability was found in Custom-Content-Width 1.0. It has been declared as problematic. Affected by this vulnerability is the function override_content_width/register_settings of the file custom-content-width.php. The manipulation leads to cross site ... Read more
Affected Products : custom-content-width- EPSS Score: %0.17
- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-10074
A vulnerability was found in OpenSeaMap online_chart 1.2. It has been classified as problematic. Affected is the function init of the file index.php. The manipulation of the argument mtext leads to cross site scripting. It is possible to launch the attack... Read more
Affected Products : online_chart- EPSS Score: %0.06
- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2015-10073
A vulnerability, which was classified as problematic, was found in tinymighty WikiSEO 1.2.1 on MediaWiki. This affects the function modifyHTML of the file WikiSEO.body.php of the component Meta Property Tag Handler. The manipulation of the argument conten... Read more
Affected Products : wikiseo- EPSS Score: %0.14
- Published: Feb. 06, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-10072
A vulnerability classified as problematic was found in NREL api-umbrella-web 0.7.1. This vulnerability affects unknown code of the component Flash Message Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgra... Read more
- EPSS Score: %0.07
- Published: Feb. 04, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-10071
A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpassword.php. The manipulation leads to weak password recovery. The complexity o... Read more
Affected Products : ez_publish_modern_legacy- EPSS Score: %0.07
- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10070
A vulnerability was found in copperwall Twiddit. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation leads to sql injection. The identifier of the patch is 2203d4ce9810bdaccece5c48ff4888658a01a... Read more
Affected Products : twiddit- EPSS Score: %0.04
- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10069
A vulnerability was found in viakondratiuk cash-machine. It has been declared as critical. This vulnerability affects the function is_card_pin_at_session/update_failed_attempts of the file machine.py. The manipulation leads to sql injection. The name of t... Read more
Affected Products : cash-machine- EPSS Score: %0.04
- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10068
A vulnerability classified as critical was found in danynab movify-j. This vulnerability affects the function getByMovieId of the file app/business/impl/ReviewServiceImpl.java. The manipulation of the argument movieId/username leads to sql injection. The ... Read more
Affected Products : movify-j- EPSS Score: %0.04
- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024