A vulnerability was found in QlikTech Qlikview up to 11.20 SR11. It has been declared as critical. This vulnerability affects unknown code of the file AccessPoint.aspx of the component XML Data Handler. The manipulation leads to xml external entity reference.
This vulnerability was named CVE-2015-3623. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Magento. Affected is the function getCsvFile. The manipulation of the argument popularity[field_expr] leads to sql injection.
This vulnerability is traded as CVE-2015-1397. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in Pimcore. Affected is an unknown function of the file admin/asset/add-asset-compatibility. The manipulation of the argument dir leads to path traversal.
This vulnerability is traded as CVE-2015-4425. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in HP WebInspect 10.1/10.2/10.3/10.4. This issue affects some unknown processing. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2015-2125. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Citrix Netscaler 10.5. Affected by this vulnerability is an unknown functionality of the component HTTP Header Handler. The manipulation of the argument Content-type leads to improper access controls.
This vulnerability is known as CVE-2015-2841. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Citrix Netscaler 10.5 and classified as critical. This issue affects some unknown processing of the file application/octet-stream of the component AppFirewall. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2015-2841. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector 3.3.0/3.4.0. Affected is an unknown function of the component API Handler. The manipulation leads to injection.
This vulnerability is traded as CVE-2025-20337. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Cisco Identity Services Engine Software 3.3.0/3.4.0. It has been classified as critical. Affected is an unknown function of the component API. The manipulation leads to injection.
This vulnerability is traded as CVE-2025-20281. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in McAfee Total Protection up to 16.0.29. This affects an unknown part of the component MTP Self-Defense. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2021-23874. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.