NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23615 | CVE-2015-1254 | core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 24127 | CVE-2015-1926 | Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 and 11.1.1.9.0, and the Oracle Applications Framework component in Oracle E-Business Suite 12.2.3 and 12.2.4, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Portal. | 2 | 5.5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 24383 | CVE-2015-2315 | Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI. | 2 | 4.3 | Medium | 2017-01-19 | 2015-03-18 | View | |
| 25151 | CVE-2015-3274 | Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service. | 2 | 4.3 | Medium | 2017-01-19 | 2016-03-01 | View | |
| 25663 | CVE-2015-4185 | The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202. | 2 | 6.9 | Medium | 2017-01-19 | 2017-01-04 | View |
Page 2285 of 17672, showing 5 records out of 88360 total, starting on record 11421, ending on 11425