Latest CVE Feed
-
4.3
MEDIUMCVE-2015-3904
Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) pin, (2) start_day, (3) start_month, (4) start_year, (5) end_da... Read more
Affected Products : roomcloud- Published: May. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4135
Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : phpwind- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-4134
Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.... Read more
Affected Products : phpwind- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-4133
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a di... Read more
Affected Products : reflex_gallery- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4132
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4127
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-regi... Read more
Affected Products : church_admin- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4084
Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value_ parameter in a check_stat action to wp-admin/admin-ajax.php.... Read more
Affected Products : free_counter- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3165
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentic... Read more
- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-1551
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-1550
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-1392
Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1389
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to tips/tipsLoginSubmit.action.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2014-6628
Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.... Read more
Affected Products : clearpass_policy_manager- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-1157
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by A... Read more
- Published: May. 28, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in... Read more
Affected Products : gigpress- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4065
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-ne... Read more
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-4064
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/p... Read more
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-4063
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/... Read more
Affected Products : newstatpress- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-4062
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.... Read more
Affected Products : newstatpress- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-3922
Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.... Read more
Affected Products : coppermine_photo_gallery- Published: May. 27, 2015
- Modified: Apr. 12, 2025