Latest CVE Feed
-
10.0
HIGHCVE-2014-8383
The InFocus IN3128HD projector with firmware 0.26 allows remote attackers to bypass authentication via a direct request to main.html.... Read more
- EPSS Score: %4.50
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0738
Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.... Read more
- EPSS Score: %0.26
- Published: May. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-0735
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970.... Read more
Affected Products : unified_customer_voice_portal- EPSS Score: %0.11
- Published: May. 17, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-9204
Stack-based buffer overflow in OPCTest.exe in Rockwell Automation RSLinx Classic before 3.73.00 allows remote attackers to execute arbitrary code via a crafted CSV file.... Read more
- EPSS Score: %0.02
- Published: May. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0730
The SMB module in Cisco Wide Area Application Services (WAAS) 6.0(1) allows remote attackers to cause a denial of service (module reload) via an invalid field in a Negotiate Protocol request, aka Bug ID CSCuo75645.... Read more
Affected Products : wide_area_application_services- EPSS Score: %0.46
- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0729
Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a file-inclusion attack, aka Bug ID CSCuu11005.... Read more
Affected Products : secure_access_control_server- EPSS Score: %0.26
- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-0726
The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122, and 7.5.x and 7.6.x before 7.6.120 allows remote authenticated users to cause a denial of service (device crash) via unspec... Read more
- EPSS Score: %0.64
- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-0723
The wireless web-authentication subsystem on Cisco Wireless LAN Controller (WLC) devices 7.5.x and 7.6.x before 7.6.120 allows remote attackers to cause a denial of service (process crash and device restart) via a crafted value, aka Bug ID CSCum03269.... Read more
- EPSS Score: %0.46
- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-0717
Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID CSCut19546.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.09
- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-0736
Cross-site request forgery (CSRF) vulnerability in Cisco MediaSense 10.5(1) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu16728.... Read more
Affected Products : mediasense- EPSS Score: %0.11
- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-0731
The ISDN implementation in Cisco IOS 15.3S allows remote attackers to cause a denial of service (device reload) via malformed Q931 SETUP messages, aka Bug ID CSCut37890.... Read more
Affected Products : ios- EPSS Score: %0.26
- Published: May. 16, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-2810
Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a den... Read more
- EPSS Score: %1.62
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3989
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors.... Read more
Affected Products : concrete5- EPSS Score: %0.26
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3325
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.... Read more
Affected Products : wp_symposium- EPSS Score: %1.90
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2250
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to index.php/dashboard/system/conversations/bannedwords/success, (2) channel pa... Read more
Affected Products : concrete5- EPSS Score: %0.48
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0734
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email Security Appliance (ESA) 8.5.6-106 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCut87743.... Read more
- EPSS Score: %0.26
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0728
Cross-site scripting (XSS) vulnerability in Cisco Access Control Server (ACS) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuu11002.... Read more
- EPSS Score: %0.26
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0727
Cross-site scripting (XSS) vulnerability in the HTTP module in Cisco Security Manager (CSM) 4.7(0)SP1(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27789.... Read more
Affected Products : security_manager- EPSS Score: %0.26
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0724
Multiple cross-site scripting (XSS) vulnerabilities in dncs 7.0.0.12 in Cisco Headend Digital Broadband Delivery System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID C... Read more
Affected Products : headend_digital_broadband_delivery_system- EPSS Score: %0.26
- Published: May. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0634
Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuq86310.... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.42
- Published: May. 15, 2015
- Modified: Apr. 12, 2025