NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 36800 | CVE-2013-0457 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid. | 2 | 3.5 | Low | 2017-01-18 | 2013-02-20 | View | |
| 85185 | CVE-2016-6519 | Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-26 | View | |
| 86721 | CVE-2017-9547 | admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the Navigation Title or Page Title of a page that is scheduled for future publication (aka a pending page change). | 2 | 3.5 | Low | 2017-06-17 | 2017-06-15 | View | |
| 26561 | CVE-2015-5399 | Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment. | 2 | 3.5 | Low | 2017-01-19 | 2016-08-29 | View | |
| 29377 | CVE-2014-0483 | The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI. | 2 | 3.5 | Low | 2017-01-19 | 2017-01-06 | View |
Page 2766 of 17672, showing 5 records out of 88360 total, starting on record 13826, ending on 13830