NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26726 | CVE-2015-5612 | Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-04 | View | |
| 26727 | CVE-2015-5618 | Chiyu BF-630 and BF-630W fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify (a) Voice Time Set configuration settings via a request to voice.htm or (b) UniFinger configuration settings via a request to bf.htm, a different vulnerability than CVE-2015-2871. | 2 | 7.5 | High | 2017-01-19 | 2015-08-03 | View | |
| 26728 | CVE-2015-5621 | The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet. | 2 | 7.5 | High | 2017-01-19 | 2016-12-23 | View | |
| 26729 | CVE-2015-5622 | Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-07 | View | |
| 26730 | CVE-2015-5623 | WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php. | 2 | 4 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 14665 of 17672, showing 5 records out of 88360 total, starting on record 73321, ending on 73325