Vulnerabilities (CVE)

Total 396934 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-0925 1 Ipass 1 Ipass Open Mobile 2026-06-17 9.0 HIGH N/A
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated by a UNC share pathname.
CVE-2015-0924 1 Ceragon 3 Fiberair Ip-10c, Fiberair Ip-10e, Fiberair Ip-10g 2026-06-17 7.8 HIGH N/A
Ceragon FibeAir IP-10 bridges have a default password for the root account, which makes it easier for remote attackers to obtain access via a (1) HTTP, (2) SSH, (3) TELNET, or (4) CLI session.
CVE-2015-0923 1 Ektron 1 Ektron Content Management System 2026-06-17 5.0 MEDIUM N/A
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue.
CVE-2015-0922 1 Mcafee 1 Epolicy Orchestrator 2026-06-17 5.0 MEDIUM N/A
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
CVE-2015-0921 1 Mcafee 1 Epolicy Orchestrator 2026-06-17 4.0 MEDIUM N/A
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
CVE-2015-0920 1 Banner Effect Header Project 1 Banner Effect Header 2026-06-17 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to wp-admin/options-general.php.
CVE-2015-0919 1 Sefrengo 1 Sefrengo 2026-06-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.
CVE-2015-0918 1 Sefrengo 1 Sefrengo 2026-06-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the administrative backend in Sefrengo before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter to backend/main.php.
CVE-2015-0917 1 Kajona 1 Kajona 2026-06-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the backend in Kajona before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.
CVE-2015-0916 1 Cacti 1 Cacti 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
CVE-2015-0915 1 Rakus 1 Maildealer 2026-06-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in RAKUS MailDealer 11.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted attachment filename.
CVE-2015-0914 1 Kozos 1 Easyctf 2026-06-17 5.0 MEDIUM N/A
EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.
CVE-2015-0913 1 Kozos 1 Easyctf 2026-06-17 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-0912 1 Kozos 1 Easyctf 2026-06-17 6.5 MEDIUM N/A
EasyCTF before 1.4 allows remote authenticated users to write executable content to files via unspecified vectors.
CVE-2015-0911 1 Dounokouno 1 Transmitmail 2026-06-17 5.0 MEDIUM N/A
Directory traversal vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to read arbitrary files via vectors related to attachment handling.
CVE-2015-0910 1 Dounokouno 1 Transmitmail 2026-06-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to inject arbitrary web script or HTML via a crafted filename.
CVE-2015-0907 1 Lhaplus 1 Lhaplus 2026-06-17 6.8 MEDIUM N/A
Buffer overflow in Lhaplus before 1.70 allows remote attackers to execute arbitrary code via a crafted archive.
CVE-2015-0906 1 Lhaplus 1 Lhaplus 2026-06-17 5.8 MEDIUM N/A
Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive.
CVE-2015-0905 1 Bblog Project 1 Bblog 2026-06-17 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users.
CVE-2015-0904 1 Shidax 1 Restaurant Karaoke 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.