NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24266 | CVE-2015-2107 | HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges. | 2 | 6.8 | Medium | 2017-01-19 | 2015-11-24 | View | |
24778 | CVE-2015-2781 | Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
25290 | CVE-2015-3624 | Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-05 | View | |
25802 | CVE-2015-4344 | The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching. | 2 | 5 | Medium | 2017-01-19 | 2016-06-09 | View | |
26314 | CVE-2015-5022 | IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields. | 2 | 4.3 | Medium | 2017-01-19 | 2015-10-07 | View |
Page 15769 of 17672, showing 5 records out of 88360 total, starting on record 78841, ending on 78845