NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25556 | CVE-2015-3986 | Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 25555 | CVE-2015-3983 | The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-30 | View | |
| 25554 | CVE-2015-3982 | The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 25553 | CVE-2015-3981 | SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037. | 2 | 5 | Medium | 2017-01-19 | 2017-01-02 | View | |
| 25552 | CVE-2015-3980 | SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View |
Page 3250 of 17672, showing 5 records out of 88360 total, starting on record 16246, ending on 16250