NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26400  CVE-2015-5149  Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp.    5.5  Medium  2017-01-19  2016-12-07  View
26656  CVE-2015-5519  Cross-site scripting (XSS) vulnerability in the applyConvolution demo in WideImage 11.02.19 allows remote attackers to inject arbitrary web script or HTML via the matrix parameter to demo/index.php.    4.3  Medium  2017-01-19  2015-08-13  View
27936  CVE-2015-7278  Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authentication of arbitrary users.    6.8  Medium  2017-01-19  2016-11-28  View
28192  CVE-2015-7713  OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.    Medium  2017-01-19  2016-12-07  View
29728  CVE-2014-0888  IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors.    4.9  Medium  2017-01-19  2014-08-29  View

Page 1174 of 17672, showing 5 records out of 88360 total, starting on record 5866, ending on 5870

Actions