CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91386  CVE-2016-4567  Candidate  Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."  Assigned (20160507)  None (candidate not yet proposed)    View
26106  CVE-2007-2749  Candidate  SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action.  Assigned (20070517)  None (candidate not yet proposed)    View
91642  CVE-2016-4823  Candidate  Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors.  Assigned (20160517)  None (candidate not yet proposed)    View
26362  CVE-2007-3005  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2789. Reason: This candidate is a duplicate of CVE-2007-2789. Notes: All CVE users should reference CVE-2007-2789 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20070604)  None (candidate not yet proposed)    View
91898  CVE-2016-5079  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160526)  None (candidate not yet proposed)    View

Page 20504 of 20943, showing 5 records out of 104715 total, starting on record 102516, ending on 102520

Actions