NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26019 | CVE-2015-4655 | Cross-site scripting (XSS) vulnerability in Synology DiskStation Manager (DSM) before 5.2-5565 Update 1 allows remote attackers to inject arbitrary web script or HTML via the "compound" parameter to entry.cgi. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26020 | CVE-2015-4656 | Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station before 6.3-2945 allow remote attackers to inject arbitrary web script or HTML via the (1) success parameter to login.php or (2) crafted URL parameters to index.php, as demonstrated by the t parameter to photo/. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26021 | CVE-2015-4657 | Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26022 | CVE-2015-4658 | Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd parameter. | 2 | 7.5 | High | 2017-01-19 | 2015-06-19 | View | |
| 26023 | CVE-2015-4659 | Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 14520 of 17672, showing 5 records out of 88360 total, starting on record 72596, ending on 72600