NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25627  CVE-2015-4135  Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter.    4.3  Medium  2017-01-19  2016-12-30  View
25626  CVE-2015-4134  Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.    5.8  Medium  2017-01-19  2016-12-30  View
25625  CVE-2015-4133  Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.    7.5  High  2017-01-19  2016-11-28  View
25624  CVE-2015-4132  Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.    3.5  Low  2017-01-19  2016-12-05  View
25623  CVE-2015-4129  SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.    6.5  Medium  2017-01-19  2016-11-28  View

Page 3234 of 17672, showing 5 records out of 88360 total, starting on record 16166, ending on 16170

Actions