Latest CVE Feed
-
5.0
MEDIUMCVE-2015-6830
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct ... Read more
Affected Products : phpmyadmin- EPSS Score: %30.43
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6290
Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.... Read more
- EPSS Score: %0.48
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6288
Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620... Read more
Affected Products : content_security_management_appliance- EPSS Score: %0.71
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6287
Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic that leads to DNS resolution delays, aka Bug IDs CSCur32005 and CSCur07907.... Read more
- EPSS Score: %0.72
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2015-6286
Cisco Application Visibility and Control (AVC) 15.3(3)JA, when FlexConnect is enabled, allows remote attackers to cause a denial of service (access-point outage) via a crafted UDP packet, aka Bug ID CSCuu47016.... Read more
Affected Products : application_visibility_and_control- EPSS Score: %0.17
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-6285
Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.... Read more
- EPSS Score: %0.44
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-4499
Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain n... Read more
Affected Products : bugzilla- EPSS Score: %2.07
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2013
IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.... Read more
Affected Products : websphere_mq- EPSS Score: %0.59
- Published: Sep. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5630
Cross-site scripting (XSS) vulnerability in the NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID.... Read more
Affected Products : japan_connected-free_wi-fi- EPSS Score: %0.31
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5629
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.... Read more
Affected Products : japan_connected-free_wi-fi- EPSS Score: %0.40
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-6921
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : zendesk_feedback_tab- EPSS Score: %0.32
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6920
Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.... Read more
Affected Products : sourceafrica- EPSS Score: %2.49
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6919
Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.... Read more
Affected Products : googlesearch- EPSS Score: %0.22
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-7216
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.... Read more
Affected Products : messenger- EPSS Score: %5.59
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6915
SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "user" cookie to plugins/feedback/pages/feedback.php.... Read more
Affected Products : resourcespace- EPSS Score: %0.32
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6914
Absolute path traversal vulnerability in SiteFactory CMS 5.5.9 allows remote attackers to read arbitrary files via a full pathname in the file parameter to assets/download.aspx.... Read more
Affected Products : sitefactory_cms- EPSS Score: %0.36
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6913
Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/down... Read more
Affected Products : download_station- EPSS Score: %0.30
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6912
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.... Read more
Affected Products : video_station- EPSS Score: %29.73
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6911
SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.... Read more
Affected Products : video_station- EPSS Score: %1.58
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6910
SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.... Read more
Affected Products : video_station- EPSS Score: %0.63
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025