NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18235 | CVE-2016-1912 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php. | 2 | 3.5 | Low | 2017-01-19 | 2016-01-21 | View | |
| 84795 | CVE-2017-7309 | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, 2.1.3, and 2.2.3. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-11 | View | |
| 85307 | CVE-2016-4866 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-22 | View | |
| 24123 | CVE-2015-1922 | The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors. | 2 | 3.5 | Low | 2017-01-19 | 2015-07-20 | View | |
| 31291 | CVE-2014-3012 | Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs. | 2 | 3.5 | Low | 2017-01-19 | 2014-06-21 | View |
Page 2601 of 17672, showing 5 records out of 88360 total, starting on record 13001, ending on 13005