CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
26618 | CVE-2007-3261 | Candidate | Cross-site scripting (XSS) vulnerability in widgets/widget_search.php in dKret before 2.6 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). | Assigned (20070619) | None (candidate not yet proposed) | View | |
92154 | CVE-2016-5335 | Candidate | VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors. | Assigned (20160607) | None (candidate not yet proposed) | View | |
26874 | CVE-2007-3517 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts. | Assigned (20070703) | None (candidate not yet proposed) | View | |
92410 | CVE-2016-5591 | Candidate | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5593. | Assigned (20160616) | None (candidate not yet proposed) | View | |
27130 | CVE-2007-3773 | Candidate | Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators. | Assigned (20070715) | None (candidate not yet proposed) | View |
Page 20505 of 20943, showing 5 records out of 104715 total, starting on record 102521, ending on 102525