Latest CVE Feed
-
5.5
MEDIUMCVE-2015-4322
Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine f... Read more
Affected Products : content_security_management_appliance- EPSS Score: %0.17
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4308
The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuu43968.... Read more
Affected Products : edge_bluebird_operating_system- EPSS Score: %0.25
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4301
Cisco NX-OS on Nexus 9000 devices 11.1(1c) allows remote authenticated users to cause a denial of service (device hang) via large files that are copied to a device's filesystem, aka Bug ID CSCuu77225.... Read more
Affected Products : nx-os nx-os nexus_93120tx nexus_93128tx nexus_9332pq nexus_9336pq_aci_spine nexus_9372px nexus_9372tx- EPSS Score: %0.82
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-4299
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- EPSS Score: %0.55
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-4298
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- EPSS Score: %0.55
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1830
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.... Read more
- EPSS Score: %88.00
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-4302
The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.70
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-4297
Open redirect vulnerability in Cisco WebEx Node for Media Convergence Server (MCS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted HTTP request parameters, aka Bug ID CSCuv32136.... Read more
Affected Products : webex_node_for_mcs- EPSS Score: %0.06
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2502
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.... Read more
- Actively Exploited
- EPSS Score: %22.56
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6519
SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail parameter in a signup action to members.php.... Read more
Affected Products : arab_portal- EPSS Score: %1.98
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6518
Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) droptable parameter, or (3) table parameter to phpliteadmin.php.... Read more
Affected Products : phpliteadmin- EPSS Score: %1.20
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6517
Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that drop database tables via the droptable parameter to phpliteadmin.php.... Read more
Affected Products : phpliteadmin- EPSS Score: %0.30
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-5515
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging acce... Read more
Affected Products : views_bulk_operations- EPSS Score: %0.56
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-5514
Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled, allows user-assisted remote attackers to inject arbitrary web script or HTML via a destination field label.... Read more
Affected Products : migrate- EPSS Score: %0.36
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5513
Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer blocks" permission to inject arbitrary web script or HTML ... Read more
- EPSS Score: %0.21
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5512
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in a URL.... Read more
Affected Products : me_aliases- EPSS Score: %0.56
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5511
The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login.... Read more
Affected Products : hybridauth_social_login- EPSS Score: %0.29
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-5510
Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destinations parameter, related to administration pa... Read more
Affected Products : content_construction_kit- EPSS Score: %0.36
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2015-5509
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors... Read more
Affected Products : administration_views- EPSS Score: %0.28
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
5.1
MEDIUMCVE-2015-5508
Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that al... Read more
Affected Products : the_extensible_catalog_drupal_toolkit- EPSS Score: %0.30
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025