NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46193 | CVE-2012-4934 | TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL. | 2 | 3.5 | Low | 2017-01-19 | 2013-08-26 | View | |
| 46705 | CVE-2012-5589 | The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link. | 2 | 3.5 | Low | 2017-01-19 | 2012-12-27 | View | |
| 51057 | CVE-2009-3891 | Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable). | 2 | 3.5 | Low | 2017-01-07 | 2009-12-17 | View | |
| 12914 | CVE-2010-1382 | Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field. | 2 | 3.5 | Low | 2017-01-18 | 2010-06-18 | View | |
| 28018 | CVE-2015-7415 | Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 2 | 3.5 | Low | 2017-01-19 | 2016-01-05 | View |
Page 14970 of 17672, showing 5 records out of 88360 total, starting on record 74846, ending on 74850