CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70149  CVE-2014-2854  Candidate  Cross-site scripting (XSS) vulnerability in the SemanticTitle extension before 1.1.0 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140414)  None (candidate not yet proposed)    View
70405  CVE-2014-3110  Candidate  Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.  Assigned (20140429)  None (candidate not yet proposed)    View
70661  CVE-2014-3365  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.  Assigned (20140507)  None (candidate not yet proposed)    View
70917  CVE-2014-3621  Candidate  The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.  Assigned (20140514)  None (candidate not yet proposed)    View
71173  CVE-2014-3877  Candidate  Incomplete blacklist vulnerability in Frams" Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup.  Assigned (20140527)  None (candidate not yet proposed)    View

Page 428 of 20943, showing 5 records out of 104715 total, starting on record 2136, ending on 2140

Actions