NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88308 | CVE-2016-6019 | IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739. | 2017-07-18 | 2017-07-17 | View | ||||
25588 | CVE-2015-4038 | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-17 | View | |
66037 | CVE-2005-0274 | Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
66805 | CVE-2005-1056 | Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
68341 | CVE-2005-2652 | Zorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3) attach.php, (4) blacklist.php, (5) zorum/forum.php, (6) globalstat.php, (7) gorum/trace.php, (8) gorum/badwords.php, or (9) gorum/flood.php. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17362 of 17672, showing 5 records out of 88360 total, starting on record 86806, ending on 86810