NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28868 | CVE-2015-8834 | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3440. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 29892 | CVE-2014-10033 | SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action. | 2 | 6.5 | Medium | 2017-01-19 | 2015-01-14 | View | |
| 30404 | CVE-2014-1840 | Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message. | 2 | 4.3 | Medium | 2017-01-19 | 2014-03-04 | View | |
| 30660 | CVE-2014-2186 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj81777. | 2 | 6.8 | Medium | 2017-01-19 | 2015-09-16 | View | |
| 30916 | CVE-2014-2494 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 15565 of 17672, showing 5 records out of 88360 total, starting on record 77821, ending on 77825