Latest CVE Feed
-
4.3
MEDIUMCVE-2014-8110
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : activemq- EPSS Score: %5.21
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0619
Memory leak in the embedded web server in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (memory consumption and SSL outage) via multiple crafted HTTP requests, aka Bug ID CSCu... Read more
- EPSS Score: %0.57
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-0611
The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-recovery account's access, which allows remote authenticated users to obtain HelpDesk-equivalent privilege... Read more
- EPSS Score: %0.61
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0610
Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Expres... Read more
Affected Products : ios- EPSS Score: %0.25
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-0608
Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers improper handlin... Read more
Affected Products : ios- EPSS Score: %0.62
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-0606
The IOS Shell in Cisco IOS allows local users to cause a denial of service (device crash) via unspecified commands, aka Bug ID CSCur59696.... Read more
Affected Products : ios- EPSS Score: %0.09
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-0592
The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers incorrect kernel-timer handling, aka Bug ID CSCuh25672.... Read more
Affected Products : ios- EPSS Score: %0.77
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-0580
Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administrators to execute arbitrary SQL commands via crafted HTTPS requests, aka Bug... Read more
Affected Products : secure_access_control_system- EPSS Score: %0.10
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3365
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID C... Read more
Affected Products : prime_security_manager- EPSS Score: %0.28
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2153
Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun21869.... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.26
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-2152
Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868.... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.17
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2147
The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to ... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.42
- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1582
Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the appid parameter in a registration task to the default URI or remote adm... Read more
Affected Products : spider_facebook- EPSS Score: %0.17
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1581
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mobile Domain plugin 1.5.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (... Read more
Affected Products : mobile_domain- EPSS Score: %0.10
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1580
Multiple cross-site request forgery (CSRF) vulnerabilities in the Redirection Page plugin 1.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting ... Read more
Affected Products : redirection- EPSS Score: %0.11
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1579
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability... Read more
Affected Products : divi- EPSS Score: %72.11
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-1578
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidvesa cookie to u5admin/pidvesa.php or (2) uri parameter to u5admin/meta2.php.... Read more
Affected Products : u5cms- EPSS Score: %3.89
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-1577
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to arbitrary files via a (1) .. (dot dot) or (2) full pathname in the f parameter.... Read more
Affected Products : u5cms- EPSS Score: %10.30
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1576
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7) c... Read more
Affected Products : u5cms- EPSS Score: %0.83
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1575
Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c, (2) i, (3) l, or (4) p parameter to index.php; the (5) a or (6) b parameter to u5admin/cookie.php; the n... Read more
Affected Products : u5cms- EPSS Score: %4.31
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025