NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
23870  CVE-2015-1604  Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/files/.    6.5  Medium  2017-01-19  2015-02-20  View
24638  CVE-2015-2617  Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.    6.5  Medium  2017-01-19  2016-12-21  View
24894  CVE-2015-2944  Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.    4.3  Medium  2017-01-19  2016-12-02  View
25150  CVE-2015-3273  mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.    Medium  2017-01-19  2016-03-01  View
25406  CVE-2015-3759  Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink.    4.6  Medium  2017-01-19  2016-12-23  View

Page 2248 of 17672, showing 5 records out of 88360 total, starting on record 11236, ending on 11240

Actions