NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25512 | CVE-2015-3908 | Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 25768 | CVE-2015-4298 | Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056. | 2 | 6.5 | Medium | 2017-01-19 | 2016-12-28 | View | |
| 26024 | CVE-2015-4660 | Cross-site scripting (XSS) vulnerability in Enhanced SQL Portal 5.0.7961 allows remote attackers to inject arbitrary web script or HTML via the id parameter to iframe.php. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26536 | CVE-2015-5352 | The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 26792 | CVE-2015-5715 | The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors. | 2 | 4 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 14575 of 17672, showing 5 records out of 88360 total, starting on record 72871, ending on 72875