NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 83385 | CVE-2017-6491 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (tooltip_id, callback, args, cid) passed to the EPESI-master/modules/Utils/Tooltip/req.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-20 | View | |
| 83897 | CVE-2015-8310 | Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist. | 2 | 3.5 | Low | 2017-03-29 | 2017-03-29 | View | |
| 83386 | CVE-2017-6492 | SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization. | 2 | 9 | High | 2017-03-29 | 2017-03-24 | View | |
| 83898 | CVE-2015-8556 | Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. | 2 | 10 | High | 2017-03-29 | 2017-03-27 | View | |
| 83899 | CVE-2015-8622 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HTML via wikitext, as demonstrated by a wikilink to a page named "javascript:alert("XSS!")." | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-27 | View |
Page 1936 of 17672, showing 5 records out of 88360 total, starting on record 9676, ending on 9680