NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21826  CVE-2016-7402  SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.    7.5  High  2017-01-19  2016-11-28  View
21825  CVE-2016-7401  The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.    Medium  2017-01-19  2016-10-04  View
81873  CVE-2016-7400  Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id parameter in a showComments expComment controller action.    7.5  High  2017-02-15  2017-02-09  View
21824  CVE-2016-7399  scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.    10  High  2017-01-30  2017-01-27  View
21823  CVE-2016-7397  The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.    2.1  Low  2017-01-19  2016-11-28  View

Page 1283 of 17672, showing 5 records out of 88360 total, starting on record 6411, ending on 6415

Actions