NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25559 | CVE-2015-3989 | Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25815 | CVE-2015-4357 | Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block. | 2 | 3.5 | Low | 2017-01-19 | 2015-06-30 | View | |
| 26071 | CVE-2015-4749 | Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect availability via vectors related to JNDI. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
| 26327 | CVE-2015-5050 | Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | 2 | 6.8 | Medium | 2017-01-19 | 2016-02-26 | View | |
| 26583 | CVE-2015-5424 | Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2885. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View |
Page 15216 of 17672, showing 5 records out of 88360 total, starting on record 76076, ending on 76080