NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35307 | CVE-2014-8085 | Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in an unspecified directory. | 2 | 6.8 | Medium | 2017-01-19 | 2015-01-06 | View | |
35563 | CVE-2014-8537 | McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs. | 2 | 2.1 | Low | 2017-01-19 | 2015-11-16 | View | |
35819 | CVE-2014-8990 | default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View | |
36075 | CVE-2014-9362 | Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web script or HTML via vectors related to deleting a Path-based Metatag. | 2 | 3.5 | Low | 2017-01-19 | 2014-12-11 | View | |
36331 | CVE-2014-9740 | Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link. | 2 | 2.1 | Low | 2017-01-19 | 2015-07-08 | View |
Page 16290 of 17672, showing 5 records out of 88360 total, starting on record 81446, ending on 81450