NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28868  CVE-2015-8834  Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3440.    4.3  Medium  2017-01-19  2016-11-28  View
29892  CVE-2014-10033  SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.    6.5  Medium  2017-01-19  2015-01-14  View
30404  CVE-2014-1840  Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.    4.3  Medium  2017-01-19  2014-03-04  View
30660  CVE-2014-2186  Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj81777.    6.8  Medium  2017-01-19  2015-09-16  View
30916  CVE-2014-2494  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.    Medium  2017-01-19  2017-01-06  View

Page 15565 of 17672, showing 5 records out of 88360 total, starting on record 77821, ending on 77825

Actions