NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
42419  CVE-2012-0287  Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.    2.6  Low  2017-01-19  2012-10-11  View
4020  CVE-2008-4164  cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.    2.6  Low  2017-01-03  2009-01-29  View
13492  CVE-2010-2001  Cross-site scripting (XSS) vulnerability in the CiviRegister module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.    2.6  Low  2017-01-18  2010-05-21  View
30900  CVE-2014-2478  Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote attackers to affect confidentiality via unknown vectors.    2.6  Low  2017-01-19  2014-10-16  View
44980  CVE-2012-3383  The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.    2.6  Low  2017-01-19  2012-09-17  View

Page 2382 of 17672, showing 5 records out of 88360 total, starting on record 11906, ending on 11910

Actions