Latest CVE Feed
-
5.0
MEDIUMCVE-2015-1887
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.... Read more
Affected Products : websphere_portal- EPSS Score: %0.28
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5123
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x th... Read more
- Actively Exploited
- EPSS Score: %45.20
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5122
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x... Read more
- Actively Exploited
- EPSS Score: %92.38
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-1961
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute a... Read more
Affected Products : business_process_manager- EPSS Score: %0.22
- Published: Jul. 13, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-4526
EMC RecoverPoint for Virtual Machines (VMs) 4.2 allows local users to obtain root-shell access by bypassing the Installation Manager Boxmgmt CLI interface.... Read more
Affected Products : recoverpoint_for_virtual_machines- EPSS Score: %0.04
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4263
The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.... Read more
- EPSS Score: %0.17
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4236
Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13... Read more
Affected Products : email_security_appliance email_security_appliance_firmware email_security_appliance- EPSS Score: %0.60
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4254
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Advanced Media Gateway devices with software 1.1(1.40) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90732.... Read more
Affected Products : telepresence_advanced_media_gateway- EPSS Score: %0.12
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3650
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer... Read more
- EPSS Score: %0.13
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2963
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonst... Read more
Affected Products : paperclip- EPSS Score: %0.48
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4259
The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by... Read more
- EPSS Score: %0.14
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-2970
index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to delete arbitrary files via the oekakis parameter.... Read more
Affected Products : simple_oekaki- EPSS Score: %1.97
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2969
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to inject arbitrary web script or HTML via the oekakis parameter.... Read more
Affected Products : simple_oekaki_bbs- EPSS Score: %0.32
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2967
Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : cacti- EPSS Score: %0.32
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4260
Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.... Read more
Affected Products : hosted_collaboration_solution- EPSS Score: %0.26
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-4244
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.... Read more
Affected Products : asr_5000_series_software- EPSS Score: %0.18
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4258
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MSE 8000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90444.... Read more
Affected Products : telepresence_mse_8000_series- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4257
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710.... Read more
Affected Products : telepresence_mcu_software- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4256
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP VCR devices with software 3.0(1.27) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90736.... Read more
Affected Products : telepresence_ip_vcr_3.0- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4255
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP Gateway devices with software 2.0(3.34) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90734.... Read more
Affected Products : telepresence_ip_gateway- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025