NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27636 | CVE-2015-6809 | Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cfg[projectName] parameter to index.php/admin/saveConfig, the (2) data[stats_provider_url] parameter to index.php/areas/saveArea, or the (3) data[description] parameter to index.php/areas/saveSection. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-04 | View | |
| 27637 | CVE-2015-6810 | Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) 4.x before 4.0.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the event_location[address] array parameter to calendar/submit/. | 2 | 3.5 | Low | 2017-01-19 | 2015-09-04 | View | |
| 27638 | CVE-2015-6811 | SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml. | 2 | 7.5 | High | 2017-01-19 | 2015-09-04 | View | |
| 27639 | CVE-2015-6812 | Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a crafted URL. | 2 | 7.8 | High | 2017-01-19 | 2015-09-04 | View | |
| 86347 | CVE-2015-6817 | PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username. | 2 | 6.8 | Medium | 2017-06-12 | 2017-06-06 | View |
Page 14850 of 17672, showing 5 records out of 88360 total, starting on record 74246, ending on 74250