NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
31750 | CVE-2014-3573 | The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML/RSDL document, related to an XML External Entity (XXE) issue. | 2 | 6.5 | Medium | 2017-01-19 | 2014-10-23 | View | |
32006 | CVE-2014-3921 | Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the z parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2014-06-24 | View | |
32262 | CVE-2014-4246 | Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP. | 2 | 3.5 | Low | 2017-01-19 | 2017-01-06 | View | |
32518 | CVE-2014-4545 | Multiple cross-site scripting (XSS) vulnerabilities in pq_dialog.php in the Pro Quoter plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) leftorright or (2) author parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-28 | View | |
32774 | CVE-2014-4876 | Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138. | 2 | 4.3 | Medium | 2017-01-19 | 2015-12-31 | View |
Page 450 of 17672, showing 5 records out of 88360 total, starting on record 2246, ending on 2250