|
272981
|
6.1 |
MEDIUM
Network
|
exponentcms
|
exponent_cms
|
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1177
|
2024-11-21 11:24 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272982
|
7.8 |
HIGH
Local
|
mobilis
|
mobiconnect
|
Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying the 'Ucell Internet' directory to reference a malicious mms_dll_r.dll or mediapla…
|
CWE-426
Untrusted Search Path
|
CVE-2015-0974
|
2024-11-21 11:24 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272983
|
7.5 |
HIGH
Network
|
oisf
|
libhtp
|
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-0928
|
2024-11-21 11:24 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272984
|
9.8 |
CRITICAL
Network
|
unit4
|
teta_web
|
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.
|
CWE-384
Session Fixation
|
CVE-2015-1174
|
2024-11-21 11:24 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272985
|
6.5 |
MEDIUM
Network
|
google debian
|
chrome debian_linux
|
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
|
CWE-415
Double Free
|
CVE-2015-1207
|
2024-11-21 11:24 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272986
|
9.8 |
CRITICAL
Network
|
ceragon
|
fibeair_ip-10_firmware
|
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
|
CWE-320
Key Management Errors
|
CVE-2015-0936
|
2024-11-21 11:24 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272987
|
7.8 |
HIGH
Local
|
csv2wpec-coupon_project
|
csv2wpec-coupon
|
Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-1000013
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272988
|
7.5 |
HIGH
Network
|
mypixs_project
|
mypixs
|
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
|
CWE-200
Information Exposure
|
CVE-2015-1000012
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272989
|
9.8 |
CRITICAL
Network
|
dukapress_project
|
dukapress
|
Blind SQL Injection in wordpress plugin dukapress v2.5.9
|
CWE-89
SQL Injection
|
CVE-2015-1000011
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272990
|
7.5 |
HIGH
Network
|
simple-image-manipulator_project
|
simple-image-manipulator
|
Remote file download in simple-image-manipulator v1.0 wordpress plugin
|
CWE-284
Improper Access Control
|
CVE-2015-1000010
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|