NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 23853 | CVE-2015-1580 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Redirection Page plugin 1.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (XSS) attacks via the (2) source or (3) redir parameter in an add action in the redirection-page to wp-admin/options-general.php. | 2 | 6.8 | Medium | 2017-01-19 | 2015-02-12 | View | |
| 24109 | CVE-2015-1906 | Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 2 | 3.5 | Low | 2017-01-19 | 2015-07-22 | View | |
| 24365 | CVE-2015-2281 | Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View | |
| 24621 | CVE-2015-2600 | Unspecified vulnerability in the Siebel Core - Server OM Svcs component in Oracle Siebel CRM 8.1.1, 8.2.2, and 15.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Security. | 2 | 3.5 | Low | 2017-01-19 | 2015-07-17 | View | |
| 24877 | CVE-2015-2918 | The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. | 2 | 4.3 | Medium | 2017-01-19 | 2015-12-31 | View |
Page 3248 of 17672, showing 5 records out of 88360 total, starting on record 16236, ending on 16240