NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41473 | CVE-2013-6415 | Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
41985 | CVE-2013-7249 | Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a different vulnerability than CVE-2013-7224. | 2 | 5 | Medium | 2017-01-18 | 2014-01-03 | View | |
43009 | CVE-2012-0974 | Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php. | 2 | 4.3 | Medium | 2017-01-19 | 2012-10-15 | View | |
43265 | CVE-2012-1302 | Multiple cross-site scripting (XSS) vulnerabilities in amMap 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file parameter to ammap.swf, or (3) the data_file parameter to amtimeline.swf. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
43521 | CVE-2012-1649 | Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-19 | 2012-09-10 | View |
Page 63 of 17672, showing 5 records out of 88360 total, starting on record 311, ending on 315