NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31731 | CVE-2014-3553 | mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships. | 2 | 4.9 | Medium | 2017-01-19 | 2014-07-29 | View | |
31987 | CVE-2014-3900 | Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649. | 2 | 4.3 | Medium | 2017-01-19 | 2014-09-08 | View | |
32243 | CVE-2014-4227 | Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. | 2 | 10 | High | 2017-01-19 | 2017-01-06 | View | |
32499 | CVE-2014-4518 | Cross-site scripting (XSS) vulnerability in xd_resize.php in the Contact Form by ContactMe.com plugin 2.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-02 | View | |
32755 | CVE-2014-4853 | Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file. | 2 | 4.3 | Medium | 2017-01-19 | 2014-07-10 | View |
Page 16832 of 17672, showing 5 records out of 88360 total, starting on record 84156, ending on 84160