NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
34618  CVE-2014-7181  Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in a button action on the maxbuttons-controller page to wp-admin/admin.php, related to the button creation page.    4.3  Medium  2017-01-19  2014-11-26  View
34874  CVE-2014-7518  The Bowl Expo 2014 (aka com.coreapps.android.followme.bowlexpo14) application 6.1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.    5.4  Medium  2017-01-19  2014-11-14  View
35130  CVE-2014-7837  mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.    5.5  Medium  2017-01-19  2015-09-03  View
35386  CVE-2014-8268  QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request.    6.4  Medium  2017-01-19  2015-02-02  View
35898  CVE-2014-9120  Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/.    4.3  Medium  2017-01-19  2014-12-11  View

Page 2110 of 17672, showing 5 records out of 88360 total, starting on record 10546, ending on 10550

Actions