NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
25559 | CVE-2015-3989 | Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
26071 | CVE-2015-4749 | Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect availability via vectors related to JNDI. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-23 | View | |
26327 | CVE-2015-5050 | Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | 2 | 6.8 | Medium | 2017-01-19 | 2016-02-26 | View | |
27351 | CVE-2015-6416 | Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
28375 | CVE-2015-8027 | Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 16237 of 17672, showing 5 records out of 88360 total, starting on record 81181, ending on 81185