NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 87287 | CVE-2017-3743 | If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing. | 2 | 3.5 | Low | 2017-07-18 | 2017-06-30 | View | |
| 25079 | CVE-2015-3177 | Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-30 | View | |
| 40695 | CVE-2013-5390 | Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 2 | 3.5 | Low | 2017-01-18 | 2013-10-16 | View | |
| 43511 | CVE-2012-1639 | Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters. | 2 | 3.5 | Low | 2017-01-19 | 2012-11-13 | View | |
| 87800 | CVE-2017-11163 | Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-17 | View |
Page 15135 of 17672, showing 5 records out of 88360 total, starting on record 75671, ending on 75675