NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 16715 | CVE-2016-0222 | IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-03-17 | View | |
| 29003 | CVE-2014-0060 | PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 30795 | CVE-2014-2366 | upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code. | 2 | 4 | Medium | 2017-01-19 | 2014-07-23 | View | |
| 35915 | CVE-2014-9155 | Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel. | 2 | 4 | Medium | 2017-01-19 | 2014-12-05 | View | |
| 46667 | CVE-2012-5544 | The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard. | 2 | 4 | Medium | 2017-01-19 | 2012-12-17 | View |
Page 3040 of 17672, showing 5 records out of 88360 total, starting on record 15196, ending on 15200