NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23870 | CVE-2015-1604 | Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/files/. | 2 | 6.5 | Medium | 2017-01-19 | 2015-02-20 | View | |
| 24638 | CVE-2015-2617 | Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition. | 2 | 6.5 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 24894 | CVE-2015-2944 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 25150 | CVE-2015-3273 | mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization. | 2 | 4 | Medium | 2017-01-19 | 2016-03-01 | View | |
| 25406 | CVE-2015-3759 | Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink. | 2 | 4.6 | Medium | 2017-01-19 | 2016-12-23 | View |
Page 2248 of 17672, showing 5 records out of 88360 total, starting on record 11236, ending on 11240