|
212051
|
7.5 |
HIGH
Network
|
wp-jobmanager
|
job_manager
|
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object refe…
|
CWE-200
Information Exposure
|
CVE-2015-6668
|
2024-11-21 11:35 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212052
|
6.1 |
MEDIUM
Network
|
web2py
|
web2py
|
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the _next parameter to user/l…
|
CWE-601
Open Redirect
|
CVE-2015-6961
|
2024-11-21 11:35 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212053
|
6.3 |
MEDIUM
Network
|
saltstack
|
salt_2015
|
salt before 2015.5.5 leaks git usernames and passwords to the log.
|
CWE-200
Information Exposure
|
CVE-2015-6918
|
2024-11-21 11:35 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212054
|
5.4 |
MEDIUM
Network
|
atutor
|
atutor
|
Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6521
|
2024-11-21 11:35 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212055
|
7.8 |
HIGH
Local
|
lenovo
|
system_update
|
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed …
|
CWE-77
Command Injection
|
CVE-2015-6971
|
2024-11-21 11:35 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212056
|
8.8 |
HIGH
Network
|
atlassian
|
bamboo
|
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
|
CWE-94
Code Injection
|
CVE-2015-6576
|
2024-11-21 11:35 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212057
|
6.8 |
MEDIUM
Physics
|
huawei
|
uap2105_firmware
|
Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell.
|
CWE-254
7PK - Security Features
|
CVE-2015-6592
|
2024-11-21 11:35 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212058
|
6.1 |
MEDIUM
Network
|
jsoup debian
|
jsoup debian_linux
|
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6748
|
2024-11-21 11:35 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212059
|
9.8 |
CRITICAL
Network
|
libpgf
|
libpgf
|
Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.
|
CWE-416
Use After Free
|
CVE-2015-6673
|
2024-11-21 11:35 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212060
|
6.1 |
MEDIUM
Network
|
coremail
|
coremail_xt
|
Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTML via a hyperlink in a document attachment.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6942
|
2024-11-21 11:35 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|