|
212061
|
6.1 |
MEDIUM
Network
|
modx
|
modx_revolution
|
Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6588
|
2024-11-21 11:35 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212062
|
9.8 |
CRITICAL
Network
|
wago
|
750-849_firmware 758-870_firmware
|
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
|
CWE-254
7PK - Security Features
|
CVE-2015-6473
|
2024-11-21 11:35 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212063
|
9.8 |
CRITICAL
Network
|
wago
|
750-849_firmware 750-881_firmware 758-870_firmware
|
WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.
|
CWE-255
Credentials Management
|
CVE-2015-6472
|
2024-11-21 11:35 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212064
|
9.8 |
CRITICAL
Network
|
fedoraproject ganglia
|
fedora ganglia-web
|
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2015-6816
|
2024-11-21 11:35 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212065
|
7.5 |
HIGH
Network
|
alcatel-lucent
|
home_device_manager
|
Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.
|
CWE-254
7PK - Security Features
|
CVE-2015-6498
|
2024-11-21 11:35 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212066
|
9.8 |
CRITICAL
Network
|
saltstack
|
salt_2015
|
win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.
|
CWE-534
DEPRECATED: Information Exposure Through Debug Log Files
|
CVE-2015-6941
|
2024-11-21 11:35 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212067
|
7.8 |
HIGH
Local
|
hancom
|
hangul_word_processor
|
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text ta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6585
|
2024-11-21 11:35 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212068
|
5.4 |
MEDIUM
Network
|
vindula
|
vindula
|
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6959
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212069
|
6.1 |
MEDIUM
Network
|
igcb
|
intellect_digital_core
|
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6540
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212070
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
|
CWE-94
Code Injection
|
CVE-2015-6531
|
2024-11-21 11:35 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|