NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72405 | CVE-2004-2028 | Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
7125 | CVE-2017-5487 | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
7381 | CVE-2011-0260 | The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window. | 2 | 4.6 | Medium | 2017-01-07 | 2012-01-13 | View | |
72917 | CVE-2004-2540 | readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
7637 | CVE-2011-0580 | Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2011-02-17 | View |
Page 16149 of 17672, showing 5 records out of 88360 total, starting on record 80741, ending on 80745