NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25641 | CVE-2015-4153 | Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
26153 | CVE-2015-4832 | Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.7, 11.1.2.2, and 11.1.2.3 allows remote attackers to affect integrity via vectors related to OIM Legacy UI. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
26665 | CVE-2015-5534 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators for requests that (1) put the website under maintenance via the maintenance_enable parameter or (2) conduct cross-site scripting (XSS) attacks via the maintenance_text parameter to admin/pages/maintenance. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
26921 | CVE-2015-5858 | The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
27177 | CVE-2015-6170 | Microsoft Edge allows remote attackers to gain privileges via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability." | 2 | 6.8 | Medium | 2017-01-19 | 2015-12-09 | View |
Page 1504 of 17672, showing 5 records out of 88360 total, starting on record 7516, ending on 7520