NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26646  CVE-2015-5507  Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with permission to create or edit fields to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-19  2016-11-28  View
26645  CVE-2015-5506  The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content via a search.    Medium  2017-01-19  2016-11-28  View
26644  CVE-2015-5505  The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors.    6.8  Medium  2017-01-19  2016-11-28  View
26643  CVE-2015-5504  SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.    7.5  High  2017-01-19  2016-12-07  View
26642  CVE-2015-5503  Open redirect vulnerability in the Chamilo integration module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.    5.8  Medium  2017-01-19  2015-09-03  View

Page 3025 of 17672, showing 5 records out of 88360 total, starting on record 15121, ending on 15125

Actions