NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26657 | CVE-2015-5520 | Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-17 | View | |
| 26658 | CVE-2015-5521 | Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-07-14 | View | |
| 26659 | CVE-2015-5522 | Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26660 | CVE-2015-5523 | The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26661 | CVE-2015-5528 | Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 14651 of 17672, showing 5 records out of 88360 total, starting on record 73251, ending on 73255