NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39410 | CVE-2013-3653 | Multiple cross-site scripting (XSS) vulnerabilities in the RecommendSearch feature in the management screen in LOCKON EC-CUBE before 2.12.5 allow remote attackers to inject arbitrary web script or HTML via vectors involving the rank parameter, a different vulnerability than CVE-2013-3652. | 2 | 4.3 | Medium | 2017-01-18 | 2013-10-11 | View | |
39666 | CVE-2013-3970 | Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA. | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-13 | View | |
39922 | CVE-2013-4295 | The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 5 | Medium | 2017-01-18 | 2013-10-24 | View | |
40178 | CVE-2013-4595 | The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used instead of HTTPS and makes it easier for remote attackers to obtain sensitive information via a crafted web page. | 2 | 4.3 | Medium | 2017-01-18 | 2014-06-24 | View | |
40434 | CVE-2013-4950 | Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2013-07-30 | View |
Page 16869 of 17672, showing 5 records out of 88360 total, starting on record 84341, ending on 84345