CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
84216 | CVE-2015-6939 | Candidate | Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150914) | None (candidate not yet proposed) | View | |
18936 | CVE-2006-2832 | Candidate | Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename. | Assigned (20060605) | None (candidate not yet proposed) | View | |
84472 | CVE-2015-7195 | Candidate | The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect. | Assigned (20150916) | None (candidate not yet proposed) | View | |
19192 | CVE-2006-3088 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Car Classifieds allows remote attackers to inject arbitrary web script or HTML via the make_id parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | Assigned (20060619) | None (candidate not yet proposed) | View | |
84728 | CVE-2015-7451 | Candidate | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | Assigned (20150929) | None (candidate not yet proposed) | View |
Page 20334 of 20943, showing 5 records out of 104715 total, starting on record 101666, ending on 101670