NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
32012 | CVE-2014-3933 | Cross-site scripting (XSS) vulnerability in the address components field formatter in the AddressField Tokens module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via an address field. | 2 | 3.5 | Low | 2017-01-19 | 2015-09-02 | View | |
32268 | CVE-2014-4252 | Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Security. | 2 | 5 | Medium | 2017-01-19 | 2017-01-06 | View | |
32524 | CVE-2014-4554 | Cross-site scripting (XSS) vulnerability in templates/download.php in the SS Downloads plugin before 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-28 | View | |
32780 | CVE-2014-4884 | The Conrad Hotel (aka com.wConradHotel) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.4 | Medium | 2017-01-19 | 2014-11-10 | View | |
33036 | CVE-2014-5337 | The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php. | 2 | 5 | Medium | 2017-01-19 | 2014-09-02 | View |
Page 858 of 17672, showing 5 records out of 88360 total, starting on record 4286, ending on 4290