NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 30684 | CVE-2014-2223 | Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in plog-content/uploads/archive/. | 2 | 7.5 | High | 2017-01-19 | 2015-01-08 | View | |
| 31964 | CVE-2014-3872 | Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password. | 2 | 7.5 | High | 2017-01-19 | 2015-09-29 | View | |
| 32476 | CVE-2014-4492 | libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type. | 2 | 7.5 | High | 2017-01-19 | 2016-12-06 | View | |
| 35548 | CVE-2014-8522 | The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers to obtain access. | 2 | 7.5 | High | 2017-01-19 | 2014-10-30 | View | |
| 36060 | CVE-2014-9345 | SQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a list_zone action to cgi/client.cgi. | 2 | 7.5 | High | 2017-01-19 | 2014-12-09 | View |
Page 15317 of 17672, showing 5 records out of 88360 total, starting on record 76581, ending on 76585