NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26665 | CVE-2015-5534 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators for requests that (1) put the website under maintenance via the maintenance_enable parameter or (2) conduct cross-site scripting (XSS) attacks via the maintenance_text parameter to admin/pages/maintenance. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 26921 | CVE-2015-5858 | The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 27177 | CVE-2015-6170 | Microsoft Edge allows remote attackers to gain privileges via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability." | 2 | 6.8 | Medium | 2017-01-19 | 2015-12-09 | View | |
| 27433 | CVE-2015-6546 | The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 before 11.6.0, BIG-IP AFM and PEM 11.3.0 before 11.6.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.0.0 through 11.3.0, BIG-IP PSM 11.0.0 through 11.4.1 allows remote attackers to cause a denial of service via "malicious traffic." | 2 | 6.1 | Medium | 2017-01-19 | 2015-11-09 | View | |
| 27689 | CVE-2015-6913 | Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-14 | View |
Page 3173 of 17672, showing 5 records out of 88360 total, starting on record 15861, ending on 15865