NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39933 | CVE-2013-4307 | Multiple cross-site scripting (XSS) vulnerabilities in repo/includes/EntityView.php in the Wikibase extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow (1) remote attackers to inject arbitrary web script or HTML via a label in the "In other languages" section or (2) remote administrators to inject arbitrary web script or HTML via a description. | 2 | 4.3 | Medium | 2017-01-18 | 2013-09-13 | View | |
40189 | CVE-2013-4612 | Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules. | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-17 | View | |
40445 | CVE-2013-4962 | The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors. | 2 | 5.8 | Medium | 2017-01-18 | 2013-10-07 | View | |
40701 | CVE-2013-5400 | An unspecified servlet in IBM Platform Symphony Developer Edition (DE) 5.2 and 6.1.x through 6.1.1 has hardcoded credentials, which allows remote attackers to bypass authentication and obtain "local environment" access via unknown vectors. | 2 | 10 | High | 2017-01-18 | 2014-02-14 | View | |
40957 | CVE-2013-5709 | The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value. | 2 | 8.3 | High | 2017-01-18 | 2013-09-17 | View |
Page 17518 of 17672, showing 5 records out of 88360 total, starting on record 87586, ending on 87590