NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27718  CVE-2015-6967  Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.    6.5  Medium  2017-01-19  2015-09-17  View
27717  CVE-2015-6966  Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.    6.8  Medium  2017-01-19  2015-09-17  View
27716  CVE-2015-6965  Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6) delete a form, (7) create a template, (8) update a template, (9) delete a template, or (10) conduct cross-site scripting (XSS) attacks via a crafted request to the cfg_forms page in wp-admin/admin.php.    6.8  Medium  2017-01-19  2015-09-17  View
27715  CVE-2015-6962  SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmonitor/estrutura/login/Login.actions.php.    7.5  High  2017-01-19  2016-12-21  View
86772  CVE-2015-6959  Cross-site scripting (XSS) vulnerability in Vindula 1.9.    3.5  Low  2017-06-18  2017-06-14  View

Page 2807 of 17672, showing 5 records out of 88360 total, starting on record 14031, ending on 14035

Actions