NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
24833 | CVE-2015-2853 | Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web sessions by providing a session ID. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-02 | View | |
25089 | CVE-2015-3187 | The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path. | 2 | 4 | Medium | 2017-01-19 | 2016-12-23 | View | |
25857 | CVE-2015-4413 | Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend Facebook Connect plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
26369 | CVE-2015-5107 | Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to obtain sensitive information via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-12-21 | View | |
26625 | CVE-2015-5485 | Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-19 | View |
Page 55 of 17672, showing 5 records out of 88360 total, starting on record 271, ending on 275