8.8
    High

    CVE-2015-6576

    Last Modified: 20 Apr 2025

    Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

    Published:2 Oct 2017
    8.8
    High

    CVE-2015-6568

    Last Modified: 22 Jun 2016

    Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality.

    Source:s0nk3y
    Published:14 Apr 2017
    8.8
    High

    CVE-2015-6567

    Last Modified: 22 Jun 2016

    Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.

    Source:s0nk3y
    Published:14 Apr 2017
    7.2
    High

    CVE-2015-6565

    Last Modified: 26 Jan 2017

    sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.

    Source:Federico Bento
    Published:11 Aug 2015
    6.8
    Medium

    CVE-2015-6545

    Last Modified: 2 Sept 2015

    Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.

    Source:High-Tech Bridge SA
    Published:3 Sept 2015
    8.8
    High

    CVE-2015-6541

    Last Modified: 26 Feb 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.

    Source:Sysdream
    Published:8 Apr 2016
    7.5
    High

    CVE-2015-6522

    Last Modified: 18 Aug 2015

    SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.

    Source:PizzaHatHacker
    Published:19 Aug 2015
    7.5
    High

    CVE-2015-6519

    Last Modified: 13 Jul 2015

    SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail parameter in a signup action to members.php.

    Source:ali ahmady
    Published:18 Aug 2015
    4.3
    Medium

    CVE-2015-6518

    Last Modified: 7 Jul 2015

    Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) droptable parameter, or (3) table parameter to phpliteadmin.php.

    Source:hyp3rlinx
    Published:18 Aug 2015
    6.8
    Medium

    CVE-2015-6517

    Last Modified: 7 Jul 2015

    Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that drop database tables via the droptable parameter to phpliteadmin.php.

    Source:hyp3rlinx
    Published:18 Aug 2015
    6.5
    Medium

    CVE-2015-6516

    Last Modified: 14 Jul 2015

    SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitrary SQL commands via the search parameter to ajax/ajax_search.php.

    Source:SySS GmbH
    Published:18 Aug 2015
    5
    Medium

    CVE-2015-6512

    Last Modified: 13 Jul 2015

    SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php.

    Source:Kacper Szurek
    Published:18 Aug 2015
    3.5
    Low

    CVE-2015-6494

    Last Modified: 28 Sept 2015

    Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Source:LiquidWorm
    Published:28 Oct 2015
    6.8
    Medium

    CVE-2015-6493

    Last Modified: 28 Sept 2015

    Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

    Source:LiquidWorm
    Published:28 Oct 2015
    9.8
    Critical

    CVE-2015-6420

    Last Modified: 24 Feb 2026

    Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published:15 Dec 2015
    4.3
    Medium

    CVE-2015-6402

    Last Modified: 7 Jun 2016

    Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935.

    Source:Patryk Bogdan
    Published:14 Dec 2015
    7.5
    High

    CVE-2015-6401

    Last Modified: 7 Jun 2016

    Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941.

    Source:Patryk Bogdan
    Published:14 Dec 2015
    7.8
    High

    CVE-2015-6396

    Last Modified: 14 Dec 2018

    The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.

    Source:RySh
    Published:8 Aug 2016
    6.8
    Medium

    CVE-2015-6357

    Last Modified: 12 Apr 2025

    The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.

    Published:18 Nov 2015
    7.2
    High

    CVE-2015-6306

    Last Modified: 23 Sept 2015

    Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.

    Source:Yorick Koster
    Published:25 Sept 2015
    7.2
    High

    CVE-2015-6305

    Last Modified: 22 Sept 2015

    Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by dbghelp.dll, aka Bug ID CSCuv01279. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4211.

    Source:Google Security Research
    Published:25 Sept 2015
    6.3
    Medium

    CVE-2015-6254

    Last Modified: 12 Apr 2025

    The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.

    Published:14 Apr 2015
    4.3
    Medium

    CVE-2015-6176

    Last Modified: 22 Jul 2025

    Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."

    Source:nu11secur1ty
    Published:9 Dec 2015
    7.2
    High

    CVE-2015-6174

    Last Modified: 17 Dec 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6171 and CVE-2015-6173.

    Source:Nils Sommer
    Published:9 Dec 2015
    7.2
    High

    CVE-2015-6173

    Last Modified: 17 Dec 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6171 and CVE-2015-6174.

    Source:Nils Sommer
    Published:9 Dec 2015
    7.2
    High

    CVE-2015-6171

    Last Modified: 17 Dec 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6173 and CVE-2015-6174.

    Source:Nils Sommer
    Published:9 Dec 2015
    9.3
    Critical

    CVE-2015-6168

    Last Modified: 6 Dec 2016

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6153.

    Source:Skylined
    Published:9 Dec 2015
    9.3
    Critical

    CVE-2015-6152

    Last Modified: 14 Dec 2015

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6162.

    Source:Moritz Jodeit
    Published:9 Dec 2015
    7.2
    High

    CVE-2015-6133

    Last Modified: 23 Mar 2017

    Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:9 Dec 2015
    7.2
    High

    CVE-2015-6132

    Last Modified: 23 Mar 2017

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:9 Dec 2015
    9.3
    Critical

    CVE-2015-6131

    Last Modified: 9 Dec 2015

    Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted .mcl file, aka "Media Center Library Parsing RCE Vulnerability."

    Source:Eduardo Braun Prado
    Published:9 Dec 2015
    7.2
    High

    CVE-2015-6128

    Last Modified: 23 Mar 2017

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:9 Dec 2015
    4.3
    Medium

    CVE-2015-6127

    Last Modified: 9 Dec 2015

    Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to read arbitrary files via a crafted .mcl file, aka "Windows Media Center Information Disclosure Vulnerability."

    Source:Core Security
    Published:9 Dec 2015
    9.3
    Critical

    CVE-2015-6104

    Last Modified: 16 Nov 2015

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-6103.

    Source:Google Security Research
    Published:11 Nov 2015
    9.3
    Critical

    CVE-2015-6103

    Last Modified: 16 Nov 2015

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-6104.

    Source:Google Security Research
    Published:11 Nov 2015
    2.1
    Low

    CVE-2015-6102

    Last Modified: 23 Nov 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory Information Disclosure Vulnerability."

    Source:Nils Sommer
    Published:11 Nov 2015
    6.9
    Medium

    CVE-2015-6101

    Last Modified: 23 Nov 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6100.

    Source:Nils Sommer
    Published:11 Nov 2015
    6.9
    Medium

    CVE-2015-6100

    Last Modified: 23 Nov 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6101.

    Source:Nils Sommer
    Published:11 Nov 2015
    7.2
    High

    CVE-2015-6098

    Last Modified: 23 Nov 2015

    Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of Privilege Vulnerability."

    Source:Nils Sommer
    Published:11 Nov 2015
    4.9
    Medium

    CVE-2015-6095

    Last Modified: 12 Apr 2025

    Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically proximate attackers to bypass authentication, and conduct decryption attacks against certain BitLocker configurations, by connecting to an unintended Key Distribution Center (KDC), aka "Windows Kerberos Security Feature Bypass."

    Published:11 Nov 2015
    4.3
    Medium

    CVE-2015-6086

    Last Modified: 14 Apr 2016

    Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

    Source:Ashfaq Ansari
    Published:11 Nov 2015
    9.8
    Critical

    CVE-2015-6024

    Last Modified: 4 May 2016

    ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter.

    Source:Bhadresh Patel
    Published:9 Feb 2017
    7.3
    High

    CVE-2015-6023

    Last Modified: 4 May 2016

    ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. NOTE: this issue can be combined with CVE-2015-6024 to execute arbitrary commands.

    Source:Bhadresh Patel
    Published:9 Feb 2017
    9.8
    Critical

    CVE-2015-6018

    Last Modified: 14 Oct 2015

    The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.

    Source:Karn Ganeshen
    Published:31 Dec 2015
    7.5
    High

    CVE-2015-6009

    Last Modified: 23 Sept 2015

    Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.

    Source:Mohab Ali
    Published:28 Sept 2015
    7.5
    High

    CVE-2015-6008

    Last Modified: 23 Sept 2015

    install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.

    Source:Mohab Ali
    Published:28 Sept 2015
    8.8
    High

    CVE-2015-6000

    Last Modified: 4 Oct 2017

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in test/logo/.

    Source:Benjamin Daniel Mussler
    Published:6 Feb 2020
    6.8
    Medium

    CVE-2015-5999

    Last Modified: 16 Nov 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi.

    Source:Bhadresh Patel
    Published:18 Nov 2015
    8.8
    High

    CVE-2015-5996

    Last Modified: 23 Jul 2018

    Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allows remote attackers to hijack the authentication of arbitrary users.

    Source:Nathu Nandwani
    Published:31 Dec 2015
    9.8
    Critical

    CVE-2015-5995

    Last Modified: 20 Feb 2017

    Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.

    Source:Mandeep Jadon
    Published:31 Dec 2015