NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25556  CVE-2015-3986  Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.    4.3  Medium  2017-01-19  2016-11-28  View
25555  CVE-2015-3983  The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.    4.3  Medium  2017-01-19  2016-12-30  View
25554  CVE-2015-3982  The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the session key.    Medium  2017-01-19  2016-12-05  View
25553  CVE-2015-3981  SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037.    Medium  2017-01-19  2017-01-02  View
25552  CVE-2015-3980  SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.    7.5  High  2017-01-19  2017-01-02  View

Page 3250 of 17672, showing 5 records out of 88360 total, starting on record 16246, ending on 16250

Actions