Latest CVE Feed
-
6.4
MEDIUMCVE-2015-1921
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.... Read more
Affected Products : websphere_portal- EPSS Score: %0.23
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1915
The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attac... Read more
Affected Products : endpoint_manager_family- EPSS Score: %0.28
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1911
Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0 before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM Sterling Selling and Fulfillment Suite allows remot... Read more
Affected Products : sterling_order_management sterling_selling_and_fulfillment_foundation sterling_field_sales- EPSS Score: %0.24
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-1910
Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or... Read more
Affected Products : infosphere_master_data_management_server- EPSS Score: %0.17
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1909
The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain adm... Read more
Affected Products : infosphere_master_data_management_server- EPSS Score: %0.29
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-1899
IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.... Read more
Affected Products : websphere_portal- EPSS Score: %0.67
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1896
Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : tivoli_storage_manager_fastback- EPSS Score: %33.88
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1895
IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass intended access restrictions by modifying the client behavior.... Read more
Affected Products : optim_workload_replay- EPSS Score: %0.25
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1894
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.... Read more
Affected Products : optim_workload_replay- EPSS Score: %0.10
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-0722
The network drivers in Cisco TelePresence T, Cisco TelePresence TE, and Cisco TelePresence TC before 7.3.2 allow remote attackers to cause a denial of service (process restart or device reload) via a flood of crafted IP packets, aka Bug ID CSCuj68952.... Read more
- EPSS Score: %0.43
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-0713
The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2... Read more
Affected Products : telepresence_advanced_media_gateway telepresence_server_software telepresence_mcu_software telepresence_ip_gateway telepresence_ip_vcr_1.0_converter telepresence_ip_vcr_2.4 telepresence_ip_vcr_3.0 telepresence_isdn_gw_3241 telepresence_serial_gateway telepresence_supervisor_mse_8050_software- EPSS Score: %0.49
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2014-2174
Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local network and allows physically proximate attackers to ob... Read more
- EPSS Score: %0.21
- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-0750
The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786.... Read more
Affected Products : hosted_collaboration_solution- EPSS Score: %0.53
- Published: May. 23, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-0916
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.... Read more
Affected Products : cacti- EPSS Score: %0.35
- Published: May. 22, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0915
Cross-site scripting (XSS) vulnerability in RAKUS MailDealer 11.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted attachment filename.... Read more
Affected Products : maildealer- EPSS Score: %0.32
- Published: May. 22, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0746
The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.... Read more
Affected Products : secure_access_control_server- EPSS Score: %0.47
- Published: May. 22, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the sy... Read more
Affected Products : feedwordpress- EPSS Score: %2.51
- Published: May. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3647
Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter ... Read more
Affected Products : wp-photo-album-plus- EPSS Score: %0.36
- Published: May. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2012-1978
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via a request to auth/process.php, (2) delet... Read more
- EPSS Score: %0.69
- Published: May. 21, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3912
Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configuration information by sniffing the network or sending unspecified commands.... Read more
- EPSS Score: %0.11
- Published: May. 21, 2015
- Modified: Apr. 12, 2025