NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 38854 | CVE-2013-2945 | SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands. | 2 | 6.5 | Medium | 2017-01-18 | 2014-04-03 | View | |
| 39110 | CVE-2013-3277 | Open redirect vulnerability in EMC RSA Archer GRC 5.x before 5.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 2 | 5.8 | Medium | 2017-01-18 | 2013-09-18 | View | |
| 39878 | CVE-2013-4239 | The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to cause a denial of service (memory corruption and crash) via vectors involving the virConnectListDefinedDomains API function. | 2 | 4 | Medium | 2017-01-18 | 2013-10-01 | View | |
| 40390 | CVE-2013-4882 | Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2) EPOAGENTMETA/DisplayMSAPropsDetail.do, a different vulnerability than CVE-2013-0140. | 2 | 6.5 | Medium | 2017-01-18 | 2013-08-22 | View | |
| 40646 | CVE-2013-5316 | Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-07 | View |
Page 15636 of 17672, showing 5 records out of 88360 total, starting on record 78176, ending on 78180