NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35505 | CVE-2014-8472 | CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-20 | View | |
| 35761 | CVE-2014-8870 | Open redirect vulnerability in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin before 1.1.2 for Woltlab Burning Board 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the board_url parameter. | 2 | 5.8 | Medium | 2017-01-19 | 2015-01-16 | View | |
| 36017 | CVE-2014-9281 | Cross-site scripting (XSS) vulnerability in admin/copy_field.php in MantisBT before 1.2.18 allows remote attackers to inject arbitrary web script or HTML via the dest_id field. | 2 | 4.3 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 37041 | CVE-2013-0751 | Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attackers to obtain sensitive information or possibly conduct cross-site scripting (XSS) attacks via a crafted HTML document. | 2 | 5.8 | Medium | 2017-01-18 | 2013-11-02 | View | |
| 37809 | CVE-2013-1636 | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2014-03-14 | View |
Page 14893 of 17672, showing 5 records out of 88360 total, starting on record 74461, ending on 74465