NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 16080 | CVE-2010-4845 | Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php. | 2 | 7.5 | High | 2017-01-18 | 2012-05-21 | View | |
| 20944 | CVE-2016-5771 | spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
| 86992 | CVE-2017-7876 | QNAP QTS before 4.2.6 build 20170517 allows command injection. | 2 | 7.5 | High | 2017-06-23 | 2017-06-22 | View | |
| 23760 | CVE-2015-1442 | SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a Modify Account action. NOTE: The article_id parameter to zero_view_article.php vector is already covered by CVE-2014-4034. | 2 | 7.5 | High | 2017-01-19 | 2015-02-09 | View | |
| 25552 | CVE-2015-3980 | SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View |
Page 15163 of 17672, showing 5 records out of 88360 total, starting on record 75811, ending on 75815