NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31317 | CVE-2014-3050 | IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engines, which allows remote authenticated users to discover credentials via unspecified vectors. | 2 | 3.5 | Low | 2017-01-19 | 2014-07-30 | View | |
| 35413 | CVE-2014-8318 | Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a field label title, when two fields have the same form_key. | 2 | 3.5 | Low | 2017-01-19 | 2014-10-24 | View | |
| 45397 | CVE-2012-3871 | Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter. | 2 | 3.5 | Low | 2017-01-19 | 2012-12-28 | View | |
| 65365 | CVE-2006-6822 | myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account"s username in a modified MM_recordId parameter. | 2 | 3.5 | Low | 2016-12-20 | 2011-03-07 | View | |
| 7766 | CVE-2011-0728 | Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view. | 2 | 3.5 | Low | 2017-01-07 | 2011-09-06 | View |
Page 2631 of 17672, showing 5 records out of 88360 total, starting on record 13151, ending on 13155