NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 34618 | CVE-2014-7181 | Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in a button action on the maxbuttons-controller page to wp-admin/admin.php, related to the button creation page. | 2 | 4.3 | Medium | 2017-01-19 | 2014-11-26 | View | |
| 34874 | CVE-2014-7518 | The Bowl Expo 2014 (aka com.coreapps.android.followme.bowlexpo14) application 6.1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.4 | Medium | 2017-01-19 | 2014-11-14 | View | |
| 35130 | CVE-2014-7837 | mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki. | 2 | 5.5 | Medium | 2017-01-19 | 2015-09-03 | View | |
| 35386 | CVE-2014-8268 | QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request. | 2 | 6.4 | Medium | 2017-01-19 | 2015-02-02 | View | |
| 35898 | CVE-2014-9120 | Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/. | 2 | 4.3 | Medium | 2017-01-19 | 2014-12-11 | View |
Page 2110 of 17672, showing 5 records out of 88360 total, starting on record 10546, ending on 10550