NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 41473 | CVE-2013-6415 | Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
| 35330 | CVE-2014-8111 | Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 38146 | CVE-2013-2031 | MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is then incorrectly interpreted as UTF-8 by Chrome and Firefox. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
| 40706 | CVE-2013-5405 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters. | 2 | 3.5 | Low | 2017-01-18 | 2016-12-30 | View | |
| 41474 | CVE-2013-6416 | Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View |
Page 2895 of 17672, showing 5 records out of 88360 total, starting on record 14471, ending on 14475