CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91631  CVE-2016-4812  Candidate  Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160517)  None (candidate not yet proposed)    View
26351  CVE-2007-2994  Candidate  SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a fullnews action, a different vector than CVE-2007-0693.  Assigned (20070604)  None (candidate not yet proposed)    View
91887  CVE-2016-5068  Candidate  Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.  Assigned (20160526)  None (candidate not yet proposed)    View
26607  CVE-2007-3250  Candidate  SQL injection vulnerability in mod_banners.php in Elxis CMS before 2006.4 20070613 allows remote attackers to execute arbitrary SQL commands via the mb_tracker cookie. NOTE: the product was patched without updating the version number; later downloads of 2006.4 are not affected.  Assigned (20070618)  None (candidate not yet proposed)    View
92143  CVE-2016-5324  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160606)  None (candidate not yet proposed)    View

Page 19630 of 20943, showing 5 records out of 104715 total, starting on record 98146, ending on 98150

Actions