|
211641
|
9.8 |
CRITICAL
Network
|
zcms_project
|
zcms
|
SQL injection vulnerability in ZCMS 1.1.
|
CWE-89
SQL Injection
|
CVE-2015-7346
|
2024-11-21 11:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211642
|
6.5 |
MEDIUM
Network
|
openstack
|
ironic
|
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2015-7514
|
2024-11-21 11:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211643
|
9.8 |
CRITICAL
Network
|
milton
|
webdav
|
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
|
CWE-611
XXE
|
CVE-2015-7326
|
2024-11-21 11:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211644
|
9.8 |
CRITICAL
Network
|
d-link
|
dvg-n5402sp_firmware
|
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration…
|
CWE-200
Information Exposure
|
CVE-2015-7247
|
2024-11-21 11:36 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211645
|
9.8 |
CRITICAL
Network
|
d-link
|
dvg-n5402sp_firmware
|
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obt…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2015-7246
|
2024-11-21 11:36 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211646
|
7.5 |
HIGH
Network
|
d-link
|
dvg-n5402sp_firmware
|
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage p…
|
CWE-22
Path Traversal
|
CVE-2015-7245
|
2024-11-21 11:36 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211647
|
6.1 |
MEDIUM
Network
|
emberjs
|
ember.js
|
Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before …
|
CWE-79
Cross-site Scripting
|
CVE-2015-7565
|
2024-11-21 11:36 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211648
|
9.8 |
CRITICAL
Network
|
teampass
|
teampass
|
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query…
|
CWE-89
SQL Injection
|
CVE-2015-7564
|
2024-11-21 11:36 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211649
|
8.8 |
HIGH
Network
|
teampass
|
teampass
|
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.
|
CWE-352
Origin Validation Error
|
CVE-2015-7563
|
2024-11-21 11:36 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211650
|
6.1 |
MEDIUM
Network
|
teampass
|
teampass
|
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a ro…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7562
|
2024-11-21 11:36 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|