NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
26400 | CVE-2015-5149 | Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp. | 2 | 5.5 | Medium | 2017-01-19 | 2016-12-07 | View | |
26656 | CVE-2015-5519 | Cross-site scripting (XSS) vulnerability in the applyConvolution demo in WideImage 11.02.19 allows remote attackers to inject arbitrary web script or HTML via the matrix parameter to demo/index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-13 | View | |
27936 | CVE-2015-7278 | Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authentication of arbitrary users. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
28192 | CVE-2015-7713 | OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
29728 | CVE-2014-0888 | IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-19 | 2014-08-29 | View |
Page 1174 of 17672, showing 5 records out of 88360 total, starting on record 5866, ending on 5870