NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25806 | CVE-2015-4348 | SQL injection vulnerability in the Spider Contacts module for Drupal allows remote authenticated users with the "access Spider Contacts category administration" permission to execute arbitrary SQL commands via unspecified vectors. | 2 | 6 | Medium | 2017-01-19 | 2015-06-30 | View | |
| 25805 | CVE-2015-4347 | Cross-site scripting (XSS) vulnerability in the inLinks Integration module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified path arguments. | 2 | 4.3 | Medium | 2017-01-19 | 2015-06-30 | View | |
| 25804 | CVE-2015-4346 | Cross-site scripting (XSS) vulnerability in the SMS Framework module 6.x-1.x before 6.x-1.1 for Drupal, when the "Send to phone" submodule is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to message previews. | 2 | 2.6 | Low | 2017-01-19 | 2015-06-30 | View | |
| 25803 | CVE-2015-4345 | The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote attackers to obtain sensitive information via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-06-09 | View | |
| 25802 | CVE-2015-4344 | The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching. | 2 | 5 | Medium | 2017-01-19 | 2016-06-09 | View |
Page 3198 of 17672, showing 5 records out of 88360 total, starting on record 15986, ending on 15990