NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 21891 | CVE-2016-7570 | Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes. | 2 | 4 | Medium | 2017-01-19 | 2016-10-04 | View | |
| 29059 | CVE-2014-0129 | badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2014-03-24 | View | |
| 30083 | CVE-2014-1443 | Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read. | 2 | 4 | Medium | 2017-01-19 | 2014-05-02 | View | |
| 35459 | CVE-2014-8391 | The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users" sessions via a large number of requests. | 2 | 4 | Medium | 2017-01-19 | 2016-05-27 | View | |
| 35971 | CVE-2014-9225 | The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2017-01-02 | View |
Page 14563 of 17672, showing 5 records out of 88360 total, starting on record 72811, ending on 72815