|
270721
|
9.8 |
CRITICAL
Network
|
community_events_project
|
community_events
|
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
|
CWE-89
SQL Injection
|
CVE-2015-3313
|
2024-11-21 11:29 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270722
|
9.8 |
CRITICAL
Network
|
soreco
|
xpert.line
|
Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call.
|
CWE-287
Improper Authentication
|
CVE-2015-3442
|
2024-11-21 11:29 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270723
|
7.5 |
HIGH
Network
|
vulcanjs
|
vulcan
|
TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to obtain password hashes via a cross-site scripting attack.
|
CWE-200
Information Exposure
|
CVE-2015-3454
|
2024-11-21 11:29 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270724
|
8.8 |
HIGH
Network
|
aspl
|
libaxl
|
Heap-based buffer overflow in libaxl 0.6.9 allows attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted XML document.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3450
|
2024-11-21 11:29 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270725
|
7.2 |
HIGH
Network
|
arubanetworks
|
clearpass
|
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Admin" privileges via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2015-3657
|
2024-11-21 11:29 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270726
|
7.2 |
HIGH
Network
|
arubanetworks
|
clearpass
|
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authori…
|
CWE-285
Improper Authorization
|
CVE-2015-3656
|
2024-11-21 11:29 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270727
|
8.8 |
HIGH
Network
|
arubanetworks
|
clearpass
|
Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to hijack the authentication of administrators b…
|
CWE-352
Origin Validation Error
|
CVE-2015-3655
|
2024-11-21 11:29 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270728
|
7.2 |
HIGH
Network
|
arubanetworks
|
clearpass
|
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different vulnerability than …
|
CWE-284
Improper Access Control
|
CVE-2015-3654
|
2024-11-21 11:29 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270729
|
7.2 |
HIGH
Network
|
arubanetworks
|
clearpass
|
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating system and consequen…
|
CWE-284
Improper Access Control
|
CVE-2015-3653
|
2024-11-21 11:29 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270730
|
6.1 |
MEDIUM
Network
|
zend
|
diactoros
|
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3257
|
2024-11-21 11:29 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|