Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-0657 1 Cisco 1 Ios Xr 2015-11-02 5.0 MEDIUM N/A
Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192.
CVE-2015-0659 1 Cisco 1 Ios 2015-11-02 5.0 MEDIUM N/A
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS allows remote attackers to trigger self-referential adjacencies via a crafted Autonomic Networking (AN) message, aka Bug ID CSCup62157.
CVE-2015-0661 1 Cisco 1 Ios Xr 2015-11-02 4.0 MEDIUM N/A
The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858.
CVE-2015-6032 1 Qolsys 1 Iq Panel 2015-11-02 9.3 HIGH N/A
Qolsys IQ Panel (aka QOL) before 1.5.1 has hardcoded cryptographic keys, which allows remote attackers to create digital signatures for code by leveraging knowledge of a key from a different installation.
CVE-2015-6033 1 Qolsys 1 Iq Panel 2015-11-02 9.3 HIGH N/A
Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass intended access restrictions via a modified update.
CVE-2015-6343 1 Cisco 1 Ios 2015-11-02 5.0 MEDIUM N/A
The SIP implementation in Cisco IOS 15.5(3)M on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service via crafted SIP messages, aka Bug ID CSCuv79202.
CVE-2014-9033 1 Wordpress 1 Wordpress 2015-11-02 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.
CVE-2015-8028 1 Sap 1 3d Visual Enterprise Viewer 2015-11-02 6.8 MEDIUM N/A
Multiple buffer overflows in SAP 3D Visual Enterprise Viewer (VEV) allow remote attackers to execute arbitrary code via a crafted (1) 3DM or (2) Flic Animation file.
CVE-2014-5458 1 Php-sqrl Project 1 Php-sqrl 2015-11-02 7.5 HIGH N/A
SQL injection vulnerability in sqrl_verify.php in php-sqrl allows remote attackers to execute arbitrary SQL commands via the message parameter.
CVE-2014-5399 1 Invensys 1 Wonderware Information Server 2015-11-02 7.5 HIGH N/A
SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-8029 1 Sap 1 3d Visual Enterprise Viewer 2015-11-02 6.8 MEDIUM N/A
SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted Filmbox document, which triggers memory corruption.
CVE-2014-5389 1 Content Audit Project 1 Content Audit 2015-11-02 7.5 HIGH N/A
SQL injection vulnerability in content-audit-schedule.php in the Content Audit plugin before 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "Audited content types" option in the content-audit page to wp-admin/options-general.php.
CVE-2015-8030 1 Sap 1 3d Visual Enterprise Viewer 2015-11-02 6.8 MEDIUM N/A
SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted (1) U3D, (2) LWO, (3) JPEG2000, or (4) FBX file, aka "Out-Of-Bounds Indexing" vulnerabilities.
CVE-2014-1253 1 Apple 1 Boot Camp 2015-11-02 4.7 MEDIUM N/A
AppleMNT.sys in Apple Boot Camp 5 before 5.1 allows local users to cause a denial of service (kernel memory corruption) or possibly have unspecified other impact via a malformed header in a Portable Executable (PE) file.
CVE-2015-5671 1 Techno Project Japan 1 Enisys Gw 2015-10-30 5.0 MEDIUM N/A
Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to bypass intended access restrictions and read arbitrary uploaded files via unspecified vectors.
CVE-2015-5669 1 Techno Project Japan 1 Enisys Gw 2015-10-30 6.5 MEDIUM N/A
Techno Project Japan Enisys Gw before 1.4.1 allows remote authenticated users to write to arbitrary files and consequently execute arbitrary code via unspecified vectors.
CVE-2015-5670 1 Techno Project Japan 1 Enisys Gw 2015-10-30 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-5668 1 Techno Project Japan 1 Enisys Gw 2015-10-30 7.5 HIGH N/A
SQL injection vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-6006 1 Medicomp 1 Medcin Engine 2015-10-30 7.5 HIGH N/A
The AddUserFinding implementation in Medicomp MEDCIN Engine 2.22.20153.x before 2.22.20153.226 might allow remote attackers to execute arbitrary code or cause a denial of service (integer truncation and heap-based buffer overflow) via a crafted packet on port 8190.
CVE-2015-7859 1 Joomla 1 Joomla\! 2015-10-30 5.0 MEDIUM N/A
The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.