NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23834 | CVE-2015-1561 | The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter. | 2 | 6.5 | Medium | 2017-01-19 | 2015-07-14 | View | |
| 24090 | CVE-2015-1886 | The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05 allows remote attackers to cause a denial of service (memory consumption) via crafted requests. | 2 | 7.8 | High | 2017-01-19 | 2016-08-03 | View | |
| 24346 | CVE-2015-2241 | Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a model attribute in ModelAdmin.readonly_fields, as demonstrated by a @property. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 24602 | CVE-2015-2581 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.1 and 5.2 allows remote attackers to affect confidentiality and availability via unknown vectors related to JServer. | 2 | 6.4 | Medium | 2017-01-19 | 2015-07-17 | View | |
| 24858 | CVE-2015-2896 | The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command. | 2 | 5 | Medium | 2017-01-19 | 2015-12-31 | View |
Page 2881 of 17672, showing 5 records out of 88360 total, starting on record 14401, ending on 14405