NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
24266  CVE-2015-2107  HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.    6.8  Medium  2017-01-19  2015-11-24  View
24778  CVE-2015-2781  Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.    4.3  Medium  2017-01-19  2016-12-02  View
25290  CVE-2015-3624  Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action.    5.8  Medium  2017-01-19  2016-12-05  View
25802  CVE-2015-4344  The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching.    Medium  2017-01-19  2016-06-09  View
26314  CVE-2015-5022  IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields.    4.3  Medium  2017-01-19  2015-10-07  View

Page 15769 of 17672, showing 5 records out of 88360 total, starting on record 78841, ending on 78845

Actions