10
    Critical

    CVE-2015-2845

    Last Modified: 3 Mar 2019

    The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO.

    Source:Chris McCurley
    Published:12 May 2015
    10
    Critical

    CVE-2015-2844

    Last Modified: 3 Mar 2019

    The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.

    Source:Chris McCurley
    Published:12 May 2015
    7.5
    High

    CVE-2015-2843

    Last Modified: 3 Mar 2019

    Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) user_name or (2) user_pass parameter in go_login.php or the PATH_INFO to (3) go_login/validate_credentials/admin/ or (4) index.php/go_site/go_get_user_info/.

    Source:Chris McCurley
    Published:12 May 2015
    10
    Critical

    CVE-2015-2842

    Last Modified: 3 Mar 2019

    Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in sounds/.

    Source:Chris McCurley
    Published:12 May 2015
    5
    Medium

    CVE-2015-2841

    Last Modified: 16 Mar 2015

    Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.

    Source:BGA Security
    Published:3 Apr 2015
    6.8
    Medium

    CVE-2015-2838

    Last Modified: 19 Mar 2015

    Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.

    Source:Han Sahin
    Published:3 Apr 2015
    5.3
    Medium

    CVE-2015-2826

    Last Modified: 5 Apr 2015

    WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.

    Source:ITAS Team
    Published:20 Sept 2017
    7.5
    High

    CVE-2015-2825

    Last Modified: 2 Apr 2015

    Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path parameter.

    Source:ITAS Team
    Published:21 Apr 2015
    7.5
    High

    CVE-2015-2824

    Last Modified: 10 Oct 2016

    Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm parameter in a load_combo_data action to sam-ajax-admin.php; or the (4) subscriber, (5) contributor, (6) author, (7) editor, (8) admin, or (9) sadmin parameter in a load_users action to sam-ajax-admin.php.

    Source:ITAS Team
    Published:6 Apr 2015
    6.8
    Medium

    CVE-2015-2805

    Last Modified: 10 Jun 2015

    Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.

    Source:RedTeam Pentesting
    Published:16 Jun 2015
    6
    Medium

    CVE-2015-2803

    Last Modified: 13 Oct 2017

    SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated users with permission to maintain acronyms to execute arbitrary SQL commands via the id parameter.

    Source:RedTeam Pentesting
    Published:17 Jun 2015
    9.8
    Critical

    CVE-2015-2798

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:TUNISIAN CYBER
    Published:25 Jul 2017
    10
    Critical

    CVE-2015-2797

    Last Modified: 1 Jun 2015

    Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.

    Source:Metasploit
    Published:19 Jun 2015
    9.8
    Critical

    CVE-2015-2794

    Last Modified: 6 May 2016

    The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

    Source:Marios Nicolaides
    Published:6 Feb 2017
    6.4
    Medium

    CVE-2015-2791

    Last Modified: 16 Mar 2015

    The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.

    Source:Jouko Pynnonen
    Published:30 Mar 2015
    4.3
    Medium

    CVE-2015-2790

    Last Modified: 11 Mar 2015

    Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.

    Source:Francis Provencher
    Published:30 Mar 2015
    4.4
    Medium

    CVE-2015-2789

    Last Modified: 16 Mar 2015

    Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

    Source:LiquidWorm
    Published:30 Mar 2015
    9.8
    Critical

    CVE-2015-2780

    Last Modified: 27 Mar 2015

    Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Source:Simon Waters
    Published:16 Oct 2017
    6.5
    Medium

    CVE-2015-2746

    Last Modified: 18 Mar 2015

    The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.

    Source:Han Sahin
    Published:26 Mar 2015
    6.8
    Medium

    CVE-2015-2701

    Last Modified: 16 Mar 2015

    Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.

    Source:Luis Santana
    Published:25 Mar 2015
    5
    Medium

    CVE-2015-2682

    Last Modified: 19 Mar 2015

    Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.

    Source:Han Sahin
    Published:26 Mar 2015
    6.8
    Medium

    CVE-2015-2680

    Last Modified: 10 Mar 2015

    Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.

    Source:LiquidWorm
    Published:23 Mar 2015
    7.5
    High

    CVE-2015-2679

    Last Modified: 10 Mar 2015

    Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php.

    Source:LiquidWorm
    Published:23 Mar 2015
    4.3
    Medium

    CVE-2015-2678

    Last Modified: 10 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.

    Source:LiquidWorm
    Published:23 Mar 2015
    4.6
    Medium

    CVE-2015-2572

    Last Modified: 17 Apr 2015

    Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.

    Source:sajith
    Published:16 Apr 2015
    6.5
    Medium

    CVE-2015-2564

    Last Modified: 6 Mar 2015

    SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php.

    Source:ITAS Team
    Published:20 Mar 2015
    7.5
    High

    CVE-2015-2562

    Last Modified: 19 Dec 2016

    Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids in a displayproducts action to index.php.

    Source:Brandon Perry
    Published:20 Mar 2015
    7.2
    High

    CVE-2015-2554

    Last Modified: 2 Nov 2015

    The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:14 Oct 2015
    7.2
    High

    CVE-2015-2553

    Last Modified: 15 Oct 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easier for local users to gain privileges by leveraging certain sandbox access, aka "Windows Mount Point Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:14 Oct 2015
    8.2
    High

    CVE-2015-2546

    Last Modified: 22 Apr 2026

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

    Published:9 Sept 2015
    7.2
    High

    CVE-2015-2528

    Last Modified: 15 Sept 2015

    Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2524.

    Source:Google Security Research
    Published:9 Sept 2015
    7.2
    High

    CVE-2015-2527

    Last Modified: 15 Sept 2015

    The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:9 Sept 2015
    7.2
    High

    CVE-2015-2525

    Last Modified: 15 Sept 2015

    Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass intended filesystem restrictions and delete arbitrary files via unspecified vectors, aka "Windows Task File Deletion Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:9 Sept 2015
    7.2
    High

    CVE-2015-2524

    Last Modified: 15 Sept 2015

    Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2528.

    Source:Google Security Research
    Published:9 Sept 2015
    9.3
    Critical

    CVE-2015-2523

    Last Modified: 16 Sept 2015

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:9 Sept 2015
    9.3
    Critical

    CVE-2015-2521

    Last Modified: 16 Sept 2015

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:9 Sept 2015
    9.3
    Critical

    CVE-2015-2520

    Last Modified: 16 Sept 2015

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:9 Sept 2015
    6.9
    Medium

    CVE-2015-2518

    Last Modified: 22 Sept 2015

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2546.

    Source:Nils Sommer
    Published:9 Sept 2015
    6.9
    Medium

    CVE-2015-2517

    Last Modified: 22 Sept 2015

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2518, and CVE-2015-2546.

    Source:Nils Sommer
    Published:9 Sept 2015
    7.2
    High

    CVE-2015-2512

    Last Modified: 24 Sept 2015

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2507.

    Source:Nils Sommer
    Published:9 Sept 2015
    6.9
    Medium

    CVE-2015-2511

    Last Modified: 22 Sept 2015

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2517, CVE-2015-2518, and CVE-2015-2546.

    Source:Nils Sommer
    Published:9 Sept 2015
    9.3
    Critical

    CVE-2015-2510

    Last Modified: 16 Sept 2015

    Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "Graphics Component Buffer Overflow Vulnerability."

    Source:Google Security Research
    Published:9 Sept 2015
    9.3
    Critical

    CVE-2015-2509

    Last Modified: 11 Sept 2015

    Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability."

    Source:R-73eN
    Published:9 Sept 2015
    7.2
    High

    CVE-2015-2508

    Last Modified: 15 Sept 2015

    The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:9 Sept 2015
    7.2
    High

    CVE-2015-2507

    Last Modified: 22 Sept 2015

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2512.

    Source:Nils Sommer
    Published:9 Sept 2015
    9.3
    Critical

    CVE-2015-2482

    Last Modified: 1 Dec 2016

    The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted replace operation with a JavaScript regular expression, aka "Scripting Engine Memory Corruption Vulnerability."

    Source:Skylined
    Published:14 Oct 2015
    9.3
    Critical

    CVE-2015-2470

    Last Modified: 21 Aug 2015

    Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Integer Underflow Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2469

    Last Modified: 21 Aug 2015

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2468

    Last Modified: 21 Aug 2015

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office for Mac 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Word Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2467

    Last Modified: 21 Aug 2015

    Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015