|
212411
|
8.8 |
HIGH
Network
|
realtyna
|
realtyna_property_listing
|
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests th…
|
CWE-352
Origin Validation Error
|
CVE-2015-7715
|
2024-11-21 11:37 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212412
|
7.2 |
HIGH
Network
|
realtyna
|
realtyna_property_listing
|
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in…
|
CWE-89
SQL Injection
|
CVE-2015-7714
|
2024-11-21 11:37 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212413
|
9.8 |
CRITICAL
Network
|
form_manager_project
|
form_manager
|
Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote attackers to execute arbitrary code via unspecifi…
|
CWE-77
Command Injection
|
CVE-2015-7806
|
2024-11-21 11:37 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212414
|
9.8 |
CRITICAL
Network
|
openbsd fedoraproject
|
opensmtpd fedora
|
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mt…
|
CWE-416
Use After Free
|
CVE-2015-7687
|
2024-11-21 11:37 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212415
|
5.9 |
MEDIUM
Network
|
gurunavi
|
gournavi
|
Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-the-middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-7778
|
2024-11-21 11:37 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212416
|
7.1 |
HIGH
Network
|
huawei
|
rh2288_v3_firmware rh2288h_v3_firmware xh628_v3_firmware rh1288_v3_firmware rh2288a_v2_firmware rh1288a_v2_firmware rh8100_v3_firmware ch222_v3_firmware ch220_v3_firmware c…
|
Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with s…
|
CWE-275
Permission Issues
|
CVE-2015-7842
|
2024-11-21 11:37 |
2017-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212417
|
6.1 |
MEDIUM
Network
|
compass_rose_project
|
compass_rose
|
Cross-site scripting (XSS) vulnerability in the Compass Rose module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7980
|
2024-11-21 11:37 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212418
|
8.8 |
HIGH
Network
|
huawei
|
fusionserver_rh8100_v3 fusionserver_rh1288a_v2 fusionserver_rh2288a_v2 fusionserver_rh1288_v3 fusionserver_rh2288h_v3 fusionserver_rh2288_v3 fusionserver_ch220_v3 fusionserver_ch…
|
The management interface on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R00…
|
CWE-254
7PK - Security Features
|
CVE-2015-7843
|
2024-11-21 11:37 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212419
|
9.8 |
CRITICAL
Network
|
huawei
|
fusionserver_rh8100_v3 fusionserver_rh1288a_v2 fusionserver_rh2288a_v2 fusionserver_rh1288_v3 fusionserver_rh2288h_v3 fusionserver_rh2288_v3 fusionserver_ch220_v3 fusionserver_ch…
|
The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V10…
|
CWE-77
Command Injection
|
CVE-2015-7841
|
2024-11-21 11:37 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212420
|
9.8 |
CRITICAL
Network
|
support_ticket_system_project
|
support_ticket_system
|
Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user …
|
CWE-89
SQL Injection
|
CVE-2015-7670
|
2024-11-21 11:37 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|