NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25627 | CVE-2015-4135 | Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 25626 | CVE-2015-4134 | Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. | 2 | 5.8 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 25625 | CVE-2015-4133 | Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 25624 | CVE-2015-4132 | Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors. | 2 | 3.5 | Low | 2017-01-19 | 2016-12-05 | View | |
| 25623 | CVE-2015-4129 | SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 3234 of 17672, showing 5 records out of 88360 total, starting on record 16166, ending on 16170