Latest CVE Feed
-
7.5
HIGHCVE-2014-8154
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vec... Read more
- EPSS Score: %0.89
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-5211
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.... Read more
Affected Products : reflection_ftp_client- EPSS Score: %2.38
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1374
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cross-site scripting (XSS), (2) SQL injection, or (3) unre... Read more
Affected Products : ferretcms- EPSS Score: %1.64
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1373
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search request, (2) username in a login request, which is not properl... Read more
Affected Products : ferretcms- EPSS Score: %5.46
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1372
SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php.... Read more
Affected Products : ferretcms- EPSS Score: %1.37
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1371
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in custom/uploads/.... Read more
Affected Products : ferretcms- EPSS Score: %9.23
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1370
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.... Read more
Affected Products : marked- EPSS Score: %0.35
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1369
SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter.... Read more
- EPSS Score: %0.36
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/... Read more
Affected Products : tower- EPSS Score: %6.84
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1367
SQL injection vulnerability in index.php in CatBot 0.4.2 allows remote attackers to execute arbitrary SQL commands via the lastcatbot parameter.... Read more
Affected Products : catbot- EPSS Score: %0.42
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1366
Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.... Read more
Affected Products : pixabay_images- EPSS Score: %3.42
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1365
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.... Read more
Affected Products : pixabay_images- EPSS Score: %21.98
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1364
SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/.... Read more
Affected Products : articlefr- EPSS Score: %0.91
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1363
Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/.... Read more
Affected Products : articlefr- EPSS Score: %0.33
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1362
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file.... Read more
Affected Products : exif_pilot- EPSS Score: %6.27
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1361
platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which might allow remote attackers to cause a denial of service ... Read more
Affected Products : chrome- EPSS Score: %0.83
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1360
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improperly handled during text drawing, related to gpu/GrBitmapT... Read more
Affected Products : chrome- EPSS Score: %0.89
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1359
Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted PDF document,... Read more
Affected Products : chrome- EPSS Score: %0.85
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-0232
The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) via cr... Read more
Affected Products : php- EPSS Score: %54.80
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that le... Read more
Affected Products : php- EPSS Score: %86.24
- Published: Jan. 27, 2015
- Modified: Apr. 12, 2025