NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25856 | CVE-2015-4398 | Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages. | 2 | 5.8 | Medium | 2017-01-19 | 2015-06-25 | View | |
| 25855 | CVE-2015-4397 | Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack the authentication of users with the "access node template" permission for requests that delete node templates via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2015-06-16 | View | |
| 25854 | CVE-2015-4396 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Keyword Research module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to hijack the authentication of users with the "kwresearch admin site keywords" permission for requests that (1) create, (2) delete, or (3) set priorities to keywords via unspecified vectors. | 2 | 5.1 | Medium | 2017-01-19 | 2016-06-27 | View | |
| 25853 | CVE-2015-4395 | The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user for a password when registering" option is enabled, which allows remote authenticated users with certain permissions to obtain sensitive information by leveraging access to the database. | 2 | 3.5 | Low | 2017-01-19 | 2016-06-09 | View | |
| 25852 | CVE-2015-4394 | The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-06-09 | View |
Page 3188 of 17672, showing 5 records out of 88360 total, starting on record 15936, ending on 15940