NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28224 | CVE-2015-7772 | Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican application, a different vulnerability than CVE-2015-7771. | 2 | 4.3 | Medium | 2017-01-19 | 2015-11-20 | View | |
| 28225 | CVE-2015-7773 | Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php extension. | 2 | 6.5 | Medium | 2017-01-19 | 2015-11-20 | View | |
| 28226 | CVE-2015-7774 | PC-EGG pWebManager before 3.3.10, and before 2.2.2 for PHP 4.x, allows remote authenticated users to execute arbitrary OS commands by leveraging the editor role. | 2 | 6.5 | Medium | 2017-01-19 | 2015-11-16 | View | |
| 28227 | CVE-2015-7775 | Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197. | 2 | 3.5 | Low | 2017-01-19 | 2016-06-21 | View | |
| 28228 | CVE-2015-7776 | Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196. | 2 | 4.3 | Medium | 2017-01-19 | 2016-06-21 | View |
Page 14973 of 17672, showing 5 records out of 88360 total, starting on record 74861, ending on 74865