NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48490 | CVE-2009-1202 | WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705. | 2 | 4.3 | Medium | 2017-01-07 | 2010-05-04 | View | |
36251 | CVE-2014-9605 | WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a " (single quote) character in the login and password parameters to webupgrade/webupgrade.php. NOTE: this was originally reported as an SQL injection vulnerability, but this may be inaccurate. | 2 | 9.4 | High | 2017-01-19 | 2015-09-04 | View | |
52386 | CVE-2007-0154 | Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
83394 | CVE-2017-6504 | WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-07 | View | |
83393 | CVE-2017-6503 | WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-13 | View |
Page 262 of 17672, showing 5 records out of 88360 total, starting on record 1306, ending on 1310