NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27431 | CVE-2015-6541 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest. | 2 | 6.8 | Medium | 2017-01-19 | 2016-04-11 | View | |
| 27687 | CVE-2015-6911 | SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi. | 2 | 7.5 | High | 2017-01-19 | 2015-09-14 | View | |
| 27943 | CVE-2015-7285 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended access restrictions via a spoofed HSxx response. | 2 | 5.8 | Medium | 2017-01-19 | 2015-11-25 | View | |
| 28199 | CVE-2015-7728 | Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to inject arbitrary web script or HTML via the username, aka SAP Security Note 2153898. | 2 | 3.5 | Low | 2017-01-19 | 2015-10-16 | View | |
| 28455 | CVE-2015-8150 | Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file. | 2 | 6.3 | Medium | 2017-01-19 | 2016-12-05 | View |
Page 3135 of 17672, showing 5 records out of 88360 total, starting on record 15671, ending on 15675