NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25863 | CVE-2015-4426 | SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/asset/grid-proxy. | 2 | 7.5 | High | 2017-01-19 | 2016-06-09 | View | |
| 25862 | CVE-2015-4425 | Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility. | 2 | 4.9 | Medium | 2017-01-19 | 2015-08-19 | View | |
| 25861 | CVE-2015-4420 | Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a host profile, or the (3) plugin_args parameter to a Test service check page. | 2 | 4.3 | Medium | 2017-01-19 | 2016-06-15 | View | |
| 25860 | CVE-2015-4418 | Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | 2 | 5 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 25859 | CVE-2015-4415 | Multiple directory traversal vulnerabilities in func.php in Magnifica Webscripts Anima Gallery 2.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) theme or (2) lang cookie parameter to AnimaGallery/. | 2 | 5 | Medium | 2017-01-19 | 2016-06-15 | View |
Page 3186 of 17672, showing 5 records out of 88360 total, starting on record 15926, ending on 15930