Latest CVE Feed
-
7.8
HIGHCVE-2015-6271
Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta... Read more
Affected Products : ios_xe ios_xe asr_1001 asr_1002 asr_1002-x asr_1004 asr_1006 asr_1013 asr_1001-x- EPSS Score: %0.43
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6270
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv6 packet, aka Bug ID CSCsv98555.... Read more
Affected Products : ios_xe ios_xe asr_1001 asr_1002 asr_1002-x asr_1004 asr_1006 asr_1013 asr_1001-x- EPSS Score: %0.43
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6269
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted (1) IPv4 or (2) IPv6 packet, aka Bug ID CSCsw69990.... Read more
Affected Products : ios_xe ios_xe asr_1001 asr_1002 asr_1002-x asr_1004 asr_1006 asr_1013 asr_1001-x- EPSS Score: %0.43
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-4036
Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_... Read more
Affected Products : linux_kernel- EPSS Score: %0.10
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-2135
Unspecified vulnerability in HP Intelligent Provisioning 1.00 through 1.62(a), 2.00, and 2.10 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : intelligent_provisioning- EPSS Score: %25.87
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-6754
Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "Administer Path Breadcrumbs" permission to inject arbitrary web script or... Read more
Affected Products : path_breadcrumbs- EPSS Score: %0.18
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6753
Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) entity title, related to in-place ed... Read more
Affected Products : quick_edit- EPSS Score: %0.14
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6655
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.... Read more
Affected Products : pligg_cms- EPSS Score: %0.22
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-6752
Cross-site scripting (XSS) vulnerability in the Search API Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search index is configured to use the HTML filter processor, allows remote authenticated users with certain permissions to inject ar... Read more
Affected Products : search_api_autocomplete- EPSS Score: %0.14
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6751
Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) note added to a time entry or an (2... Read more
Affected Products : time_tracker- EPSS Score: %0.16
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-6535
Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).... Read more
Affected Products : youtube_embed- EPSS Score: %0.50
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6616
Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS Single Channel (FG-100-PB) with firmware FG-x00-PB_V2.02.0.00 allows remote attackers to inject arbitrary web script or HTML via the DEVICE_NAME parameter to cgi-bin/CFGhttp/.... Read more
- EPSS Score: %0.25
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3148
Cross-site scripting (XSS) vulnerability in libahttp/err.c in OkCupid OKWS (OK Web Server) allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to a non-existent page, which is not properly handled in a 404 error page.... Read more
Affected Products : ok_web_server- EPSS Score: %0.36
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2570
Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP Font Lib before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.... Read more
Affected Products : php_font_lib- EPSS Score: %0.42
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2014-2332
Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by remote attackers by leveragi... Read more
Affected Products : check_mk- EPSS Score: %0.52
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
8.5
HIGHCVE-2014-2331
Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.... Read more
Affected Products : check_mk- EPSS Score: %0.80
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-2330
Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authentication of users for requests that (1) upload arbitrary snapshots, (2) delete arbitrary files, or possib... Read more
Affected Products : check_mk- EPSS Score: %0.17
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2329
Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a check_mk agent, a (2) crafted request to a moni... Read more
Affected Products : check_mk- EPSS Score: %0.16
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6750
Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.... Read more
Affected Products : dl-1_sr10- EPSS Score: %6.07
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6747
Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to diffe... Read more
Affected Products : banking- EPSS Score: %0.25
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025