NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28701  CVE-2015-8604  SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.    6.5  Medium  2017-01-19  2016-12-02  View
28700  CVE-2015-8603  Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipity[entry_id] parameter in an "edit" admin action to serendipity_admin.php.    3.5  Low  2017-01-19  2016-12-07  View
28699  CVE-2015-8602  The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node.    3.5  Low  2017-01-19  2015-12-18  View
28698  CVE-2015-8601  The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors.    Medium  2017-01-19  2015-12-18  View
28697  CVE-2015-8600  The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive information, gain privileges, or have unspecified other impact via unknown vectors, aka SAP Security Note 2227855.    7.5  High  2017-01-19  2015-12-18  View

Page 2594 of 17672, showing 5 records out of 88360 total, starting on record 12966, ending on 12970

Actions