NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 31193 | CVE-2014-2863 | Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter. | 2 | 10 | High | 2017-01-19 | 2014-04-16 | View | |
| 31449 | CVE-2014-3210 | SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php. | 2 | 6.5 | Medium | 2017-01-19 | 2015-07-31 | View | |
| 31705 | CVE-2014-3522 | The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View | |
| 31961 | CVE-2014-3867 | The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984. | 2 | 5 | Medium | 2017-01-19 | 2014-06-07 | View | |
| 32217 | CVE-2014-4201 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect availability via vectors related to WLS - Web Services. | 2 | 5 | Medium | 2017-01-19 | 2015-12-01 | View |
Page 15343 of 17672, showing 5 records out of 88360 total, starting on record 76711, ending on 76715