NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 39123 | CVE-2013-3294 | Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php. | 2 | 7.5 | High | 2017-01-18 | 2014-02-21 | View | |
| 39379 | CVE-2013-3612 | Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors. | 2 | 10 | High | 2017-01-18 | 2013-09-17 | View | |
| 39635 | CVE-2013-3921 | Directory traversal vulnerability in Easytime Studio Easy File Manager 1.1 for iOS allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) to the default URI. | 2 | 5 | Medium | 2017-01-18 | 2013-12-31 | View | |
| 39891 | CVE-2013-4258 | Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to syslog. | 2 | 7.5 | High | 2017-01-18 | 2016-12-30 | View | |
| 40147 | CVE-2013-4555 | Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-18 | 2016-12-07 | View |
Page 14656 of 17672, showing 5 records out of 88360 total, starting on record 73276, ending on 73280