Latest CVE Feed
-
6.5
MEDIUMCVE-2015-7773
Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php ex... Read more
Affected Products : kirby- EPSS Score: %0.44
- Published: Nov. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7772
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment i... Read more
Affected Products : applican- EPSS Score: %0.32
- Published: Nov. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7771
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID that is encountered by an applican appli... Read more
Affected Products : applican- EPSS Score: %0.32
- Published: Nov. 20, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8087
Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with software before V800R007C00SPC100 allows remote attackers to send packets to other VPNs and conduct flooding attacks via a crafted MPLS f... Read more
- EPSS Score: %0.22
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-8083
An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V200R003C00SPC300 does not properly initialize memory when processing timeout messages, which allows remote attackers to cause a deni... Read more
- EPSS Score: %0.23
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-7984
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that exec... Read more
- EPSS Score: %1.48
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7845
The exception handling mechanism in the CLI Module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V100R001C20SPH605 allows remote attackers to cause a denial of service (CLI outage) via crafted SSH pack... Read more
- EPSS Score: %0.22
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7385
Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject arbitrary web script or HTML via the uid field in a PGP public key, which is not properly handled in "Guard PGP Settings."... Read more
Affected Products : ox_guard- EPSS Score: %0.26
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2015-0794
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.... Read more
- EPSS Score: %0.05
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9756
The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.... Read more
- EPSS Score: %0.66
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8236
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.... Read more
Affected Products : eos- EPSS Score: %6.02
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-7910
Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the response body.... Read more
Affected Products : telemetry_web_server- EPSS Score: %0.26
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4112
The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scri... Read more
Affected Products : enterprise_server- EPSS Score: %0.22
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6374
The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attac... Read more
- EPSS Score: %0.22
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-6371
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-6370
The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.... Read more
- EPSS Score: %0.32
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-6369
The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531.... Read more
- EPSS Score: %0.10
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6368
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.... Read more
- EPSS Score: %0.08
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-8090
The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request.... Read more
Affected Products : loglogic_unity- EPSS Score: %0.14
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8053
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052.... Read more
Affected Products : coldfusion- EPSS Score: %0.75
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025