NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 37623 | CVE-2013-1409 | Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php. | 2 | 4.3 | Medium | 2017-01-18 | 2014-03-04 | View | |
| 37879 | CVE-2013-1717 | Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname. | 2 | 5.4 | Medium | 2017-01-18 | 2017-01-06 | View | |
| 38135 | CVE-2013-2019 | Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple file_signature elements. | 2 | 9.3 | High | 2017-01-18 | 2014-06-03 | View | |
| 38391 | CVE-2013-2327 | Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1635. | 2 | 10 | High | 2017-01-18 | 2013-06-06 | View | |
| 38647 | CVE-2013-2705 | Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings. | 2 | 6.8 | Medium | 2017-01-18 | 2014-05-14 | View |
Page 14966 of 17672, showing 5 records out of 88360 total, starting on record 74826, ending on 74830