NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
83385  CVE-2017-6491  Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (tooltip_id, callback, args, cid) passed to the EPESI-master/modules/Utils/Tooltip/req.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.    4.3  Medium  2017-03-29  2017-03-20  View
83897  CVE-2015-8310  Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.    3.5  Low  2017-03-29  2017-03-29  View
83386  CVE-2017-6492  SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.    High  2017-03-29  2017-03-24  View
83898  CVE-2015-8556  Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.    10  High  2017-03-29  2017-03-27  View
83899  CVE-2015-8622  Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HTML via wikitext, as demonstrated by a wikilink to a page named "javascript:alert("XSS!")."    4.3  Medium  2017-03-29  2017-03-27  View

Page 1936 of 17672, showing 5 records out of 88360 total, starting on record 9676, ending on 9680

Actions