NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
41473  CVE-2013-6415  Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.    4.3  Medium  2017-01-18  2016-12-30  View
41985  CVE-2013-7249  Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a different vulnerability than CVE-2013-7224.    Medium  2017-01-18  2014-01-03  View
43009  CVE-2012-0974  Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php.    4.3  Medium  2017-01-19  2012-10-15  View
43265  CVE-2012-1302  Multiple cross-site scripting (XSS) vulnerabilities in amMap 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file parameter to ammap.swf, or (3) the data_file parameter to amtimeline.swf.    4.3  Medium  2017-07-18  2017-07-17  View
43521  CVE-2012-1649  Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.    4.9  Medium  2017-01-19  2012-09-10  View

Page 63 of 17672, showing 5 records out of 88360 total, starting on record 311, ending on 315

Actions