|
212351
|
9.8 |
CRITICAL
Network
|
huawei
|
fusionserver_rh8100_v3 fusionserver_rh1288a_v2 fusionserver_rh2288a_v2 fusionserver_rh1288_v3 fusionserver_rh2288h_v3 fusionserver_rh2288_v3 fusionserver_ch220_v3 fusionserver_ch…
|
The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V10…
|
CWE-77
Command Injection
|
CVE-2015-7841
|
2024-11-21 11:37 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212352
|
9.8 |
CRITICAL
Network
|
support_ticket_system_project
|
support_ticket_system
|
Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user …
|
CWE-89
SQL Injection
|
CVE-2015-7670
|
2024-11-21 11:37 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212353
|
4.6 |
MEDIUM
Physics
|
huawei
|
s9300_firmware s9700_firmware s7700_firmware ar200_firmware ar1200_firmware ar2200_firmware ar3200_firmware
|
Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2015-7846
|
2024-11-21 11:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212354
|
5.9 |
MEDIUM
Network
|
comicsmart
|
ganma\!
|
GANMA! App for iOS does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-7785
|
2024-11-21 11:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212355
|
5.5 |
MEDIUM
Local
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus kernel-rt enterprise_mrg
|
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot re…
|
CWE-254
7PK - Security Features
|
CVE-2015-7837
|
2024-11-21 11:37 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212356
|
4.3 |
MEDIUM
Network
|
drupal
|
drupal
|
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and …
|
CWE-200
Information Exposure
|
CVE-2015-7880
|
2024-11-21 11:37 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212357
|
5.4 |
MEDIUM
Network
|
stickynote_project
|
stickynote
|
Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x before 7.x-1.3 for Drupal allows remote authenticated users with permission to create or edit a stickynote to inject arbitrary we…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7879
|
2024-11-21 11:37 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212358
|
9.8 |
CRITICAL
Network
|
user_dashboard_project
|
user_dashboard
|
Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-7877
|
2024-11-21 11:37 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212359
|
5.3 |
MEDIUM
Network
|
qt
|
qtwebkit
|
qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.
|
CWE-200
Information Exposure
|
CVE-2015-8079
|
2024-11-21 11:37 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212360
|
5.4 |
MEDIUM
Network
|
centreon
|
centreon
|
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
|
CWE-79
Cross-site Scripting
|
CVE-2015-7672
|
2024-11-21 11:37 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|