NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26637 | CVE-2015-5498 | The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not check the view permission for the shipments overview (admin/shipwire/shipments), which allows remote attackers to obtain sensitive information via a request to the page. | 2 | 5 | Medium | 2017-01-19 | 2015-09-03 | View | |
| 26638 | CVE-2015-5499 | The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify custom widgets and create widget database records by leveraging the "navigate view" permission. | 2 | 4 | Medium | 2017-01-19 | 2015-08-19 | View | |
| 26639 | CVE-2015-5500 | Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | 2 | 3.5 | Low | 2017-01-19 | 2015-08-19 | View | |
| 26640 | CVE-2015-5501 | The Hostmaster (Aegir) module 6.x-2.x before 6.x-2.4 and 7.x-3.x before 7.x-3.0-beta2 for Drupal allows remote attackers to execute arbitrary PHP code via a crafted file in the directory used to write Apache vhost files for hosted sites in a multi-site environment. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 26641 | CVE-2015-5502 | The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View |
Page 14647 of 17672, showing 5 records out of 88360 total, starting on record 73231, ending on 73235