Vulnerabilities (CVE)

Total 396934 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-10016 1 Opensim-utils Project 1 Opensim-utils 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability, which was classified as critical, has been found in jeff-kelley opensim-utils. Affected by this issue is the function DatabaseForRegion of the file regionscrits.php. The manipulation of the argument region leads to sql injection. The patch is identified as c29e5c729a833a29dbf5b1e505a0553fe154575e. It is recommended to apply a patch to fix this issue. VDB-217550 is the identifier assigned to this vulnerability.
CVE-2015-10015 1 Glidernet 1 Ogn-live 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability, which was classified as critical, has been found in glidernet ogn-live. This issue affects some unknown processing. The manipulation leads to sql injection. The patch is named bc0f19965f760587645583b7624d66a260946e01. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217487.
CVE-2015-10014 1 Uke Project 1 Uke 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability classified as critical has been found in arekk uke. This affects an unknown part of the file lib/uke/finder.rb. The manipulation leads to sql injection. The identifier of the patch is 52fd3b2d0bc16227ef57b7b98a3658bb67c1833f. It is recommended to apply a patch to fix this issue. The identifier VDB-217485 was assigned to this vulnerability.
CVE-2015-10013 1 Webdevstudios 1 Taxonomy Switcher 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3 on WordPress. It has been classified as problematic. Affected is the function taxonomy_switcher_init of the file taxonomy-switcher.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.4 is able to address this issue. It is recommended to upgrade the affected component. VDB-217446 is the identifier assigned to this vulnerability.
CVE-2015-10012 1 Sumocoders 1 Frameworkuserbundle 2026-06-17 2.7 LOW 3.5 LOW
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Resources/views/Security/login.html.twig. The manipulation leads to information exposure through error message. Upgrading to version 1.4.0 is able to address this issue. The name of the patch is abe4993390ba9bd7821ab12678270556645f94c8. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217268. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2015-10011 1 Cisco 1 Openresolve 2026-06-17 4.1 MEDIUM 4.6 MEDIUM
A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improper output neutralization for logs. The identifier of the patch is 9eba6ba5abd89d0e36a008921eb307fcef8c5311. It is recommended to apply a patch to fix this issue. The identifier VDB-217197 was assigned to this vulnerability.
CVE-2015-10010 1 Cisco 1 Openresolve 2026-06-17 2.6 LOW 3.1 LOW
A vulnerability was found in OpenDNS OpenResolve. It has been rated as problematic. Affected by this issue is the function get of the file resolverapi/endpoints.py of the component API. The manipulation leads to cross site scripting. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The name of the patch is c680170d5583cd9342fe1af43001fe8b2b8004dd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217196.
CVE-2015-10009 1 Nonfiction 1 Nterchange 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file app/controllers/code_caller_controller.php. The manipulation of the argument q with the input %5C%27%29;phpinfo%28%29;/* leads to code injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.1 is able to address this issue. The patch is named fba7d89176fba8fe289edd58835fe45080797d99. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217187.
CVE-2015-10008 1 Weipdcrm Project 1 Weipdcrm 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the patch is 43bad79392332fa39e31b95268e76fbda9fec3a4. It is recommended to apply a patch to fix this issue. The identifier VDB-217185 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2015-10007 1 Weipdcrm Project 1 Weipdcrm 2026-06-17 4.0 MEDIUM 3.5 LOW
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is 43bad79392332fa39e31b95268e76fbda9fec3a4. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217184. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2015-10006 1 Ingnovarq Project 1 Ingnovarq 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of the patch is 9d18a39944d79dfedacd754a742df38f99d3c0e2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217172.
CVE-2015-10005 1 Markdown-it Project 1 Markdown-it 2026-06-17 N/A 3.5 LOW
A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is 89c8620157d6e38f9872811620d25138fc9d1b0d. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216852.
CVE-2015-10004 1 Json Web Token Project 1 Json Web Token 2026-06-17 N/A 7.5 HIGH
Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.
CVE-2015-10003 1 Filezilla-project 1 Filezilla Server 2026-06-17 N/A 4.3 MEDIUM
A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the attack remotely. Upgrading to version 0.9.51 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2015-10002 1 Kiddoware 1 Kids Place 2026-06-17 2.1 LOW 5.3 MEDIUM
A vulnerability classified as problematic has been found in Kiddoware Kids Place. This affects the Home Button Protection. A repeated pressing of the button causes a local denial of service. It is recommended to upgrade the affected component.
CVE-2015-10001 1 Wp-stats Project 1 Wp-stats 2026-06-17 4.3 MEDIUM 4.3 MEDIUM
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
CVE-2015-1000013 1 Csv2wpec-coupon Project 1 Csv2wpec-coupon 2026-06-17 5.0 MEDIUM 7.8 HIGH
Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1
CVE-2015-1000012 1 Mypixs Project 1 Mypixs 2026-06-17 5.0 MEDIUM 7.5 HIGH
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
CVE-2015-1000011 1 Dukapress Project 1 Dukapress 2026-06-17 7.5 HIGH 9.8 CRITICAL
Blind SQL Injection in wordpress plugin dukapress v2.5.9
CVE-2015-1000010 1 Simple-image-manipulator Project 1 Simple-image-manipulator 2026-06-17 5.0 MEDIUM 7.5 HIGH
Remote file download in simple-image-manipulator v1.0 wordpress plugin