NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26396 | CVE-2015-5144 | Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
27420 | CVE-2015-6523 | Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the instagram-portfolio page in wp-admin/options-general.php. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-21 | View | |
27676 | CVE-2015-6858 | HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
27932 | CVE-2015-7254 | Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
28188 | CVE-2015-7707 | Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. | 2 | 6.5 | Medium | 2017-01-19 | 2015-10-06 | View |
Page 1029 of 17672, showing 5 records out of 88360 total, starting on record 5141, ending on 5145