Export limit exceeded: 338939 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (338939 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2015-9297 | 1 Pixelite | 1 Events Manager | 2024-11-21 | 6.1 Medium |
| The events-manager plugin before 5.6 for WordPress has XSS. | ||||
| CVE-2015-9296 | 1 Never5 | 1 Download Monitor | 2024-11-21 | N/A |
| The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. | ||||
| CVE-2015-9295 | 1 Bestwebsoft | 1 Contact Form | 2024-11-21 | N/A |
| The contact-form-plugin plugin before 3.96 for WordPress has XSS. | ||||
| CVE-2015-9294 | 1 Tipsandtricks-hq | 1 All In One Wp Security \& Firewall | 2024-11-21 | N/A |
| The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances. | ||||
| CVE-2015-9293 | 1 Tipsandtricks-hq | 1 All In One Wp Security \& Firewall | 2024-11-21 | N/A |
| The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. | ||||
| CVE-2015-9292 | 1 6kbbs | 1 6kbbs | 2024-11-21 | N/A |
| 6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter). | ||||
| CVE-2015-9291 | 1 Cpanel | 1 Cpanel | 2024-11-21 | N/A |
| cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221). | ||||
| CVE-2015-9290 | 1 Freetype | 1 Freetype | 2024-11-21 | N/A |
| In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again. | ||||
| CVE-2015-9289 | 2 Linux, Redhat | 3 Linux Kernel, Enterprise Linux, Rhel Extras Rt | 2024-11-21 | 5.5 Medium |
| In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23. | ||||
| CVE-2015-9288 | 1 Unity | 1 Web Player | 2024-11-21 | N/A |
| The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials | ||||
| CVE-2015-9287 | 1 Cam | 1 The University Of Cambridge Web Authentication System Apache Authentication Agent | 2024-11-21 | N/A |
| Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not signed like the rest of the message, and manipulation is therefore trivial. The "kid" field should only ever represent an integer. However, it is possible to provide any string value. An attacker could use this to their advantage to force the application agent to load the RSA public key required for message integrity checking from an unintended location. | ||||
| CVE-2015-9286 | 1 Nodebb | 1 Nodebb | 2024-11-21 | N/A |
| Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS. | ||||
| CVE-2015-9285 | 1 Esotalk | 1 Esotalk | 2024-11-21 | N/A |
| esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI. | ||||
| CVE-2015-9284 | 1 Omniauth | 1 Omniauth | 2024-11-21 | 8.8 High |
| The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. | ||||
| CVE-2015-9282 | 1 Grafana | 1 Piechart-panel | 2024-11-21 | N/A |
| The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard. | ||||
| CVE-2015-9281 | 6 Hpe, Ibm, Linux and 3 more | 6 Hp-ux Ipfilter, Aix, Linux Kernel and 3 more | 2024-11-21 | N/A |
| Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. | ||||
| CVE-2015-9280 | 1 Mailenable | 1 Mailenable | 2024-11-21 | 10.0 Critical |
| MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter. | ||||
| CVE-2015-9279 | 1 Mailenable | 1 Mailenable | 2024-11-21 | N/A |
| MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message. | ||||
| CVE-2015-9278 | 1 Mailenable | 1 Mailenable | 2024-11-21 | N/A |
| MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request. | ||||
| CVE-2015-9277 | 1 Mailenable | 1 Mailenable | 2024-11-21 | N/A |
| MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled. | ||||