Latest CVE Feed
-
4.3
MEDIUMCVE-2015-7708
Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php.... Read more
Affected Products : 4images- EPSS Score: %0.22
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-7707
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.... Read more
Affected Products : openfire- EPSS Score: %4.46
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7323
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 allows remote authenticated users to bypass intended access restrictions and log into arbitrary m... Read more
Affected Products : pulse_connect_secure- EPSS Score: %0.37
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7322
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting... Read more
Affected Products : pulse_connect_secure- EPSS Score: %0.28
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-7685
GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.... Read more
Affected Products : glpi- EPSS Score: %0.15
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-7684
Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a file with an executable extension as an attachment to a new ticket, then accessing it via a direct request to the file in files/_tmp/.... Read more
Affected Products : glpi- EPSS Score: %1.22
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7392
Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote attackers to execute arbitrary code via a trailing \u in a json string to cJSON_Parse.... Read more
Affected Products : freeswitch- EPSS Score: %3.05
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-5687
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.... Read more
Affected Products : anchor_cms- EPSS Score: %0.55
- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-4930
IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %2.38
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2031
Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.19
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2030
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.25
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2029
Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.25
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2028
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.25
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-2027
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.14
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2015-2026
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.10
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2025
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.25
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-2016
Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unknown vectors.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.86
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-2011
The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %1.03
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1988
Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 and Tivoli Storage FlashCopy Manager for VMware 3.1 before 3.1.1.3, 3.2... Read more
Affected Products : tivoli_storage_manager_for_virtual_environments tivoli_storage_flashcopy_manager- EPSS Score: %0.17
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1983
Cross-site scripting (XSS) vulnerability in the Projects page in IBM UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : urbancode_build- EPSS Score: %0.17
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025