NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26661  CVE-2015-5528  Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php.    4.3  Medium  2017-01-19  2016-12-21  View
26660  CVE-2015-5523  The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.    4.3  Medium  2017-01-19  2016-12-07  View
26659  CVE-2015-5522  Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.    6.8  Medium  2017-01-19  2016-12-07  View
26658  CVE-2015-5521  Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.    4.3  Medium  2017-01-19  2015-07-14  View
26657  CVE-2015-5520  Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account.    4.3  Medium  2017-01-19  2015-07-17  View

Page 3022 of 17672, showing 5 records out of 88360 total, starting on record 15106, ending on 15110

Actions