NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28224  CVE-2015-7772  Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican application, a different vulnerability than CVE-2015-7771.    4.3  Medium  2017-01-19  2015-11-20  View
28225  CVE-2015-7773  Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php extension.    6.5  Medium  2017-01-19  2015-11-20  View
28226  CVE-2015-7774  PC-EGG pWebManager before 3.3.10, and before 2.2.2 for PHP 4.x, allows remote authenticated users to execute arbitrary OS commands by leveraging the editor role.    6.5  Medium  2017-01-19  2015-11-16  View
28227  CVE-2015-7775  Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197.    3.5  Low  2017-01-19  2016-06-21  View
28228  CVE-2015-7776  Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196.    4.3  Medium  2017-01-19  2016-06-21  View

Page 14973 of 17672, showing 5 records out of 88360 total, starting on record 74861, ending on 74865

Actions