Latest CVE Feed
-
3.5
LOWCVE-2015-5163
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.... Read more
- EPSS Score: %0.24
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-4324
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to... Read more
Affected Products : nx-os nexus_7000 nx-os nexus_4001i nexus_3048 nexus_3548 nexus_3016 nexus_3064 nexus_31128pq nexus_3132q +18 more products- EPSS Score: %0.83
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-4322
Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine f... Read more
Affected Products : content_security_management_appliance- EPSS Score: %0.17
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4308
The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuu43968.... Read more
Affected Products : edge_bluebird_operating_system- EPSS Score: %0.25
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4301
Cisco NX-OS on Nexus 9000 devices 11.1(1c) allows remote authenticated users to cause a denial of service (device hang) via large files that are copied to a device's filesystem, aka Bug ID CSCuu77225.... Read more
Affected Products : nx-os nx-os nexus_93120tx nexus_93128tx nexus_9332pq nexus_9336pq_aci_spine nexus_9372px nexus_9372tx- EPSS Score: %0.82
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-4299
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- EPSS Score: %0.55
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-4298
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- EPSS Score: %0.55
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1830
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.... Read more
- EPSS Score: %88.00
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-4302
The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.70
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-4297
Open redirect vulnerability in Cisco WebEx Node for Media Convergence Server (MCS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted HTTP request parameters, aka Bug ID CSCuv32136.... Read more
Affected Products : webex_node_for_mcs- EPSS Score: %0.06
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2502
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.... Read more
- Actively Exploited
- EPSS Score: %22.56
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6519
SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail parameter in a signup action to members.php.... Read more
Affected Products : arab_portal- EPSS Score: %1.98
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6518
Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) droptable parameter, or (3) table parameter to phpliteadmin.php.... Read more
Affected Products : phpliteadmin- EPSS Score: %1.20
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6517
Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that drop database tables via the droptable parameter to phpliteadmin.php.... Read more
Affected Products : phpliteadmin- EPSS Score: %0.30
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-5515
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging acce... Read more
Affected Products : views_bulk_operations- EPSS Score: %0.56
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-5514
Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled, allows user-assisted remote attackers to inject arbitrary web script or HTML via a destination field label.... Read more
Affected Products : migrate- EPSS Score: %0.36
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5513
Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer blocks" permission to inject arbitrary web script or HTML ... Read more
- EPSS Score: %0.21
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5512
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in a URL.... Read more
Affected Products : me_aliases- EPSS Score: %0.56
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5511
The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login.... Read more
Affected Products : hybridauth_social_login- EPSS Score: %0.29
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-5510
Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destinations parameter, related to administration pa... Read more
Affected Products : content_construction_kit- EPSS Score: %0.36
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025