|
275971
|
- |
|
google_doc_embedder
|
google_doc_embedder
|
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an e…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1879
|
2024-11-21 11:26 |
2015-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275972
|
8.8 |
HIGH
Network
|
hp
|
airwave
|
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
|
CWE-352
Origin Validation Error
|
CVE-2015-1391
|
2024-11-21 11:25 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275973
|
6.1 |
MEDIUM
Network
|
hp
|
airwave
|
Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1390
|
2024-11-21 11:25 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275974
|
6.5 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2015-1313
|
2024-11-21 11:25 |
2023-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275975
|
8.8 |
HIGH
Network
|
atutor
|
atutor
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account vi…
|
CWE-352
Origin Validation Error
|
CVE-2015-1583
|
2024-11-21 11:25 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275976
|
9.8 |
CRITICAL
Network
|
jakweb
|
gecko_cms
|
JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities
|
CWE-20
Improper Input Validation
|
CVE-2015-1425
|
2024-11-21 11:25 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275977
|
5.4 |
MEDIUM
Network
|
10web
|
photo_gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1394
|
2024-11-21 11:25 |
2020-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275978
|
7.8 |
HIGH
Local
|
google
|
android
|
media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted appl…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2015-1530
|
2024-11-21 11:25 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275979
|
5.5 |
MEDIUM
Local
|
google
|
android
|
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.
|
CWE-20
Improper Input Validation
|
CVE-2015-1525
|
2024-11-21 11:25 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275980
|
7.5 |
HIGH
Network
|
gnu debian
|
patch debian_linux
|
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an in…
|
CWE-22
Path Traversal
|
CVE-2015-1396
|
2024-11-21 11:25 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|